Tenda AX3 firmware v16.03.12.11 contains a stack-based buffer overflow in the formGetIptv function due to improper handling of the stbpvid stack buffer, which may result in memory corruption and remote code execution.
References
| Link | Resource |
|---|---|
| https://river-brow-763.notion.site/Tenda-AX3-Buffer-Overflow-in-formGetIptv-2c9a595a7aef80e9b90fdaa56f51374b | Exploit Third Party Advisory |
| https://river-brow-763.notion.site/Tenda-AX3-Buffer-Overflow-in-formGetIptv-2c9a595a7aef80e9b90fdaa56f51374b?source=copy_link | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2026-01-22 16:16
Updated : 2026-01-26 20:39
NVD link : CVE-2025-69764
Mitre link : CVE-2025-69764
CVE.ORG link : CVE-2025-69764
JSON object : View
Products Affected
tenda
- ax3_firmware
- ax3
CWE
CWE-121
Stack-based Buffer Overflow
