High severity8.8NVD Advisory· Published Apr 4, 2025· Updated Jun 17, 2026
CVE-2025-3259
CVE-2025-3259
Description
A vulnerability, which was classified as critical, has been found in Tenda RX3 16.03.13.11. This issue affects the function formSetDeviceName of the file /goform/SetOnlineDevName. The manipulation of the argument devName leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected products
3- cpe:2.3:o:tenda:rx3_firmware:16.03.13.11_multi:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
6- sixth-action-50e.notion.site/Tenda-RX3-Buffer-Overflow-1c9f6468377380a2977cd6c3a81f453cnvdExploitThird Party Advisory
- sixth-action-50e.notion.site/Tenda-RX3-Buffer-Overflow-1c9f6468377380a2977cd6c3a81f453cnvdExploitThird Party Advisory
- vuldb.comnvdPermissions RequiredThird Party AdvisoryVDB Entry
- vuldb.comnvdThird Party AdvisoryVDB Entry
- vuldb.comnvdThird Party AdvisoryVDB Entry
- www.tenda.com.cnnvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.