PT-2025-53855 · Tenda · Tenda M3

Dwbruijn

·

Published

2025-12-28

·

Updated

2025-12-30

·

CVE-2025-15234

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Tenda M3 version 1.0.0.13
Description A flaw exists in the Tenda M3 router. The formSetRemoteInternetLanInfo function within the /goform/setInternetLanInfo file is susceptible to a heap-based buffer overflow. Manipulation of the portIp, portMask, portGateWay, portDns, and portSecDns arguments can trigger this issue. Remote attackers can potentially exploit this weakness. The exploit is publicly available.
Recommendations Tenda M3 version 1.0.0.13: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Buffer Overflow

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2026-00326
CVE-2025-15234

Affected Products

Tenda M3