VYPR

M3 Firmware

by Tenda

CVEs (45)

  • CVE-2025-15252HigDec 30, 2025
    risk 0.57cvss 8.8epss 0.03

    A flaw has been found in Tenda M3 1.0.0.13(4903). The affected element is the function formSetRemoteDhcpForAp of the file /goform/setDhcpAP. This manipulation of the argument startip/endip/leasetime/gateway/dns1/dns2 causes stack-based buffer overflow. The attack can be…

  • CVE-2025-15234HigDec 30, 2025
    risk 0.57cvss 8.8epss 0.03

    A weakness has been identified in Tenda M3 1.0.0.13(4903). Impacted is the function formSetRemoteInternetLanInfo of the file /goform/setInternetLanInfo. This manipulation of the argument portIp/portMask/portGateWay/portDns/portSecDns causes heap-based buffer overflow. It is…

  • CVE-2025-15233HigDec 30, 2025
    risk 0.57cvss 8.8epss 0.01

    A security flaw has been discovered in Tenda M3 1.0.0.13(4903). This issue affects the function formSetAdInfoDetails of the file /goform/setAdInfoDetail. The manipulation of the argument adName/smsPassword/smsAccount/weixinAccount/weixinName/smsSignature/adRedirectUrl/adCopyRight…

  • CVE-2025-15232HigDec 30, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was identified in Tenda M3 1.0.0.13(4903). This vulnerability affects the function formSetAdPushInfo of the file /goform/setAdPushInfo. The manipulation of the argument mac/terminal leads to stack-based buffer overflow. The attack is possible to be carried out…

  • CVE-2025-15231HigDec 30, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was determined in Tenda M3 1.0.0.13(4903). This affects the function formSetRemoteVlanInfo of the file /goform/setVlanInfo. Executing a manipulation of the argument ID/vlan/port can lead to stack-based buffer overflow. The attack can be executed remotely. The…

  • CVE-2025-15230HigDec 30, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in Tenda M3 1.0.0.13(4903). Affected by this issue is the function formSetVlanPolicy of the file /goform/setVlanPolicyData. Performing a manipulation of the argument qvlan_truck_port results in heap-based buffer overflow. Remote exploitation of the…

  • CVE-2025-9298HigAug 21, 2025
    risk 0.57cvss 8.8epss 0.01

    A flaw has been found in Tenda M3 1.0.0.12. Affected is the function formQuickIndex of the file /goform/QuickIndex. Executing manipulation of the argument PPPOEPassword can lead to stack-based buffer overflow. The attack can be launched remotely. The exploit has been published…

  • CVE-2022-32035HigJul 1, 2022
    risk 0.50cvss 7.5epss 0.14

    Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formMasterMng.

  • CVE-2022-38571HigAug 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda M3 V1.0.0.12(4856) was discovered to contain a buffer overflow in the function formSetGuideListItem.

  • CVE-2022-38570HigAug 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow in the function formDelPushedAd. This vulnerability allows attackers to cause a Denial of Service (DoS) via the adPushUID parameter.

  • CVE-2022-38569HigAug 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow in the function formDelAd.

  • CVE-2022-38568HigAug 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formSetFixTools. This vulnerability allows attackers to cause a Denial of Service (DoS) via the hostname parameter.

  • CVE-2022-38567HigAug 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow vulnerability in the function formSetAdConfigInfo. This vulnerability allows attackers to cause a Denial of Service (DoS) via the authIPs parameter.

  • CVE-2022-38566HigAug 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formEmailTest. This vulnerability allows attackers to cause a Denial of Service (DoS) via the mailname parameter.

  • CVE-2022-38565HigAug 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formEmailTest. This vulnerability allows attackers to cause a Denial of Service (DoS) via the mailpwd parameter.

  • CVE-2022-38564HigAug 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda M3 V1.0.0.12(4856) was discovered to contain a buffer overflow vulnerability in the function formSetPicListItem. This vulnerability allows attackers to cause a Denial of Service (DoS) via the adItemUID parameter.

  • CVE-2022-38563HigAug 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formSetFixTools. This vulnerability allows attackers to cause a Denial of Service (DoS) via the MACAddr parameter.

  • CVE-2022-38562HigAug 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formSetFixTools. This vulnerability allows attackers to cause a Denial of Service (DoS) via the lan parameter.

  • CVE-2022-32043HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formSetAccessCodeInfo.

  • CVE-2022-32041HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formGetPassengerAnalyseData.