PT-2026-3945 · Tenda · Tenda Ax3

Published

2026-01-22

·

Updated

2026-01-22

·

CVE-2025-69764

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tenda AX3 firmware version 16.03.12.11
Description The software contains a stack-based buffer overflow in the formGetIptv function. This is due to improper handling of the stbpvid stack buffer, which may lead to memory corruption and remote code execution.
Recommendations Update to a newer version of the firmware to address this issue. As a temporary workaround, consider disabling the formGetIptv function until a patch is available.

Exploit

Fix

RCE

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-69764

Affected Products

Tenda Ax3