M3
by Tenda
CVEs (46)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-38570 | Hig | 0.49 | 7.5 | 0.01 | Aug 28, 2022 | Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow in the function formDelPushedAd. This vulnerability allows attackers to cause a Denial of Service (DoS) via the adPushUID parameter. | ||
| CVE-2022-38569 | Hig | 0.49 | 7.5 | 0.01 | Aug 28, 2022 | Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow in the function formDelAd. | ||
| CVE-2022-38568 | Hig | 0.49 | 7.5 | 0.01 | Aug 28, 2022 | Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formSetFixTools. This vulnerability allows attackers to cause a Denial of Service (DoS) via the hostname parameter. | ||
| CVE-2022-38567 | Hig | 0.49 | 7.5 | 0.01 | Aug 28, 2022 | Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow vulnerability in the function formSetAdConfigInfo. This vulnerability allows attackers to cause a Denial of Service (DoS) via the authIPs parameter. | ||
| CVE-2022-38566 | Hig | 0.49 | 7.5 | 0.01 | Aug 28, 2022 | Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formEmailTest. This vulnerability allows attackers to cause a Denial of Service (DoS) via the mailname parameter. | ||
| CVE-2022-38565 | Hig | 0.49 | 7.5 | 0.01 | Aug 28, 2022 | Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formEmailTest. This vulnerability allows attackers to cause a Denial of Service (DoS) via the mailpwd parameter. | ||
| CVE-2022-38564 | Hig | 0.49 | 7.5 | 0.01 | Aug 28, 2022 | Tenda M3 V1.0.0.12(4856) was discovered to contain a buffer overflow vulnerability in the function formSetPicListItem. This vulnerability allows attackers to cause a Denial of Service (DoS) via the adItemUID parameter. | ||
| CVE-2022-38563 | Hig | 0.49 | 7.5 | 0.01 | Aug 28, 2022 | Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formSetFixTools. This vulnerability allows attackers to cause a Denial of Service (DoS) via the MACAddr parameter. | ||
| CVE-2022-38562 | Hig | 0.49 | 7.5 | 0.01 | Aug 28, 2022 | Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formSetFixTools. This vulnerability allows attackers to cause a Denial of Service (DoS) via the lan parameter. | ||
| CVE-2022-32043 | Hig | 0.49 | 7.5 | 0.01 | Jul 1, 2022 | Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formSetAccessCodeInfo. | ||
| CVE-2022-32041 | Hig | 0.49 | 7.5 | 0.01 | Jul 1, 2022 | Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formGetPassengerAnalyseData. | ||
| CVE-2022-32040 | Hig | 0.49 | 7.5 | 0.01 | Jul 1, 2022 | Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formSetCfm. | ||
| CVE-2022-32039 | Hig | 0.49 | 7.5 | 0.01 | Jul 1, 2022 | Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the listN parameter in the function fromDhcpListClient. | ||
| CVE-2022-32037 | Hig | 0.49 | 7.5 | 0.01 | Jul 1, 2022 | Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formSetAPCfg. | ||
| CVE-2022-32036 | Hig | 0.49 | 7.5 | 0.01 | Jul 1, 2022 | Tenda M3 V1.0.0.12 was discovered to contain multiple stack overflow vulnerabilities via the ssidList, storeName, and trademark parameters in the function formSetStoreWeb. | ||
| CVE-2022-32034 | Hig | 0.49 | 7.5 | 0.01 | Jul 1, 2022 | Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the items parameter in the function formdelMasteraclist. | ||
| CVE-2025-15253 | 0.00 | — | 0.01 | Dec 30, 2025 | A vulnerability has been found in Tenda M3 1.0.0.13(4903). The impacted element is an unknown function of the file /goform/exeCommand. Such manipulation of the argument cmdinput leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been… | |||
| CVE-2025-15252 | 0.00 | — | 0.03 | Dec 30, 2025 | A flaw has been found in Tenda M3 1.0.0.13(4903). The affected element is the function formSetRemoteDhcpForAp of the file /goform/setDhcpAP. This manipulation of the argument startip/endip/leasetime/gateway/dns1/dns2 causes stack-based buffer overflow. The attack can be… | |||
| CVE-2025-15234 | 0.00 | — | 0.02 | Dec 30, 2025 | A weakness has been identified in Tenda M3 1.0.0.13(4903). Impacted is the function formSetRemoteInternetLanInfo of the file /goform/setInternetLanInfo. This manipulation of the argument portIp/portMask/portGateWay/portDns/portSecDns causes heap-based buffer overflow. It is… | |||
| CVE-2025-15233 | 0.00 | — | 0.01 | Dec 30, 2025 | A security flaw has been discovered in Tenda M3 1.0.0.13(4903). This issue affects the function formSetAdInfoDetails of the file /goform/setAdInfoDetail. The manipulation of the argument adName/smsPassword/smsAccount/weixinAccount/weixinName/smsSignature/adRedirectUrl/adCopyRight… |
- risk 0.49cvss 7.5epss 0.01
Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow in the function formDelPushedAd. This vulnerability allows attackers to cause a Denial of Service (DoS) via the adPushUID parameter.
- risk 0.49cvss 7.5epss 0.01
Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow in the function formDelAd.
- risk 0.49cvss 7.5epss 0.01
Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formSetFixTools. This vulnerability allows attackers to cause a Denial of Service (DoS) via the hostname parameter.
- risk 0.49cvss 7.5epss 0.01
Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow vulnerability in the function formSetAdConfigInfo. This vulnerability allows attackers to cause a Denial of Service (DoS) via the authIPs parameter.
- risk 0.49cvss 7.5epss 0.01
Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formEmailTest. This vulnerability allows attackers to cause a Denial of Service (DoS) via the mailname parameter.
- risk 0.49cvss 7.5epss 0.01
Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formEmailTest. This vulnerability allows attackers to cause a Denial of Service (DoS) via the mailpwd parameter.
- risk 0.49cvss 7.5epss 0.01
Tenda M3 V1.0.0.12(4856) was discovered to contain a buffer overflow vulnerability in the function formSetPicListItem. This vulnerability allows attackers to cause a Denial of Service (DoS) via the adItemUID parameter.
- risk 0.49cvss 7.5epss 0.01
Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formSetFixTools. This vulnerability allows attackers to cause a Denial of Service (DoS) via the MACAddr parameter.
- risk 0.49cvss 7.5epss 0.01
Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formSetFixTools. This vulnerability allows attackers to cause a Denial of Service (DoS) via the lan parameter.
- risk 0.49cvss 7.5epss 0.01
Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formSetAccessCodeInfo.
- risk 0.49cvss 7.5epss 0.01
Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formGetPassengerAnalyseData.
- risk 0.49cvss 7.5epss 0.01
Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formSetCfm.
- risk 0.49cvss 7.5epss 0.01
Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the listN parameter in the function fromDhcpListClient.
- risk 0.49cvss 7.5epss 0.01
Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formSetAPCfg.
- risk 0.49cvss 7.5epss 0.01
Tenda M3 V1.0.0.12 was discovered to contain multiple stack overflow vulnerabilities via the ssidList, storeName, and trademark parameters in the function formSetStoreWeb.
- risk 0.49cvss 7.5epss 0.01
Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the items parameter in the function formdelMasteraclist.
- CVE-2025-15253Dec 30, 2025risk 0.00cvss —epss 0.01
A vulnerability has been found in Tenda M3 1.0.0.13(4903). The impacted element is an unknown function of the file /goform/exeCommand. Such manipulation of the argument cmdinput leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been…
- CVE-2025-15252Dec 30, 2025risk 0.00cvss —epss 0.03
A flaw has been found in Tenda M3 1.0.0.13(4903). The affected element is the function formSetRemoteDhcpForAp of the file /goform/setDhcpAP. This manipulation of the argument startip/endip/leasetime/gateway/dns1/dns2 causes stack-based buffer overflow. The attack can be…
- CVE-2025-15234Dec 30, 2025risk 0.00cvss —epss 0.02
A weakness has been identified in Tenda M3 1.0.0.13(4903). Impacted is the function formSetRemoteInternetLanInfo of the file /goform/setInternetLanInfo. This manipulation of the argument portIp/portMask/portGateWay/portDns/portSecDns causes heap-based buffer overflow. It is…
- CVE-2025-15233Dec 30, 2025risk 0.00cvss —epss 0.01
A security flaw has been discovered in Tenda M3 1.0.0.13(4903). This issue affects the function formSetAdInfoDetails of the file /goform/setAdInfoDetail. The manipulation of the argument adName/smsPassword/smsAccount/weixinAccount/weixinName/smsSignature/adRedirectUrl/adCopyRight…
Page 2 of 3