Critical severity9.8NVD Advisory· Published Jan 21, 2026· Updated Jun 17, 2026
CVE-2025-69766
CVE-2025-69766
Description
Tenda AX3 firmware v16.03.12.11 contains a stack-based buffer overflow in the formGetIptv function due to improper handling of the citytag stack buffer, which may result in memory corruption and remote code execution.
Affected products
3- cpe:2.3:o:tenda:ax3_firmware:16.03.12.11:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2- river-brow-763.notion.site/Tenda-AX3-Buffer-Overflow-in-formGetIptv-2c9a595a7aef8043a091e6722b8e255anvdExploitThird Party Advisory
- river-brow-763.notion.site/Tenda-AX3-Buffer-Overflow-in-formGetIptv-2c9a595a7aef8043a091e6722b8e255anvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.