Tenda AX3 firmware v16.03.12.11 contains a stack-based buffer overflow in the formGetIptv function due to improper handling of the citytag stack buffer, which may result in memory corruption and remote code execution.
References
| Link | Resource |
|---|---|
| https://river-brow-763.notion.site/Tenda-AX3-Buffer-Overflow-in-formGetIptv-2c9a595a7aef8043a091e6722b8e255a | Exploit Third Party Advisory |
| https://river-brow-763.notion.site/Tenda-AX3-Buffer-Overflow-in-formGetIptv-2c9a595a7aef8043a091e6722b8e255a?source=copy_link | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
26 Jan 2026, 20:38
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:h:tenda:ax3:-:*:*:*:*:*:*:* cpe:2.3:o:tenda:ax3_firmware:16.03.12.11:*:*:*:*:*:*:* |
|
| First Time |
Tenda
Tenda ax3 Tenda ax3 Firmware |
|
| References | () https://river-brow-763.notion.site/Tenda-AX3-Buffer-Overflow-in-formGetIptv-2c9a595a7aef8043a091e6722b8e255a - Exploit, Third Party Advisory | |
| References | () https://river-brow-763.notion.site/Tenda-AX3-Buffer-Overflow-in-formGetIptv-2c9a595a7aef8043a091e6722b8e255a?source=copy_link - Exploit, Third Party Advisory |
22 Jan 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-121 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
21 Jan 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-21 18:16
Updated : 2026-01-26 20:38
NVD link : CVE-2025-69766
Mitre link : CVE-2025-69766
CVE.ORG link : CVE-2025-69766
JSON object : View
Products Affected
tenda
- ax3
- ax3_firmware
CWE
CWE-121
Stack-based Buffer Overflow
