PT-2025-9581 · Tenda · Tenda Tx3
Shiny
·
Published
2025-03-03
·
Updated
2025-03-04
·
CVE-2025-1897
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Tenda TX3 version 16.03.13.11 multi
Description
A critical issue has been found in the processing of the file /goform/SetNetControlList, where the manipulation of the
list argument leads to a buffer overflow. This issue can be exploited remotely.Recommendations
For Tenda TX3 version 16.03.13.11 multi, consider restricting access to the /goform/SetNetControlList endpoint until a patch is available. As a temporary workaround, avoid using the
list argument in the affected endpoint to minimize the risk of exploitation.Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tenda Tx3