PT-2025-49583 · Tenda · Tenda Ax3
Published
2025-12-08
·
Updated
2025-12-08
·
CVE-2025-65804
CVSS v3.1
6.5
Medium
| AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Tenda AX3 version 16.03.12.11
Description
The Tenda AX3 version 16.03.12.11 contains a stack overflow in the
formSetIptv function through the iptvType parameter. This flaw can lead to memory corruption and potentially allow for remote code execution (RCE). The vulnerable API endpoint is formSetIptv and the vulnerable parameter is iptvType.Recommendations
Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the
formSetIptv function until a patch is available.Exploit
Fix
RCE
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tenda Ax3