PT-2025-54179 · Tenda · Tenda M3

Dwbruijn

·

Published

2025-12-30

·

Updated

2025-12-30

·

CVE-2025-15252

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Tenda M3 version 1.0.0.13(4903)
Description A flaw exists in Tenda M3 version 1.0.0.13(4903) that allows remote attackers to trigger a stack-based buffer overflow. The issue is located in the formSetRemoteDhcpForAp function within the /goform/setDhcpAP file. Manipulation of the startip, endip, leasetime, gateway, dns1, and dns2 arguments can cause the overflow. The exploit has been published.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Stack Overflow

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2025-15252

Affected Products

Tenda M3