PT-2025-53853 · Tenda · Tenda M3

Dwbruijn

·

Published

2025-12-28

·

Updated

2026-01-04

·

CVE-2025-15233

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Tenda M3 version 1.0.0.13(4903)
Description A security issue exists in Tenda M3 version 1.0.0.13(4903). The formSetAdInfoDetails function within the /goform/setAdInfoDetail file is susceptible to a heap-based buffer overflow. This occurs through the manipulation of the following arguments: adName, smsPassword, smsAccount, weixinAccount, weixinName, smsSignature, adRedirectUrl, adCopyRight, smsContent, and adItemUID. The issue can be exploited remotely. The exploit code for this issue is publicly available.
Recommendations For Tenda M3 version 1.0.0.13(4903), at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Heap Based Buffer Overflow

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2026-00325
CVE-2025-15233

Affected Products

Tenda M3