VYPR

M3

by Tenda

CVEs (46)

  • CVE-2022-38570HigAug 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow in the function formDelPushedAd. This vulnerability allows attackers to cause a Denial of Service (DoS) via the adPushUID parameter.

  • CVE-2022-38569HigAug 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow in the function formDelAd.

  • CVE-2022-38568HigAug 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formSetFixTools. This vulnerability allows attackers to cause a Denial of Service (DoS) via the hostname parameter.

  • CVE-2022-38567HigAug 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow vulnerability in the function formSetAdConfigInfo. This vulnerability allows attackers to cause a Denial of Service (DoS) via the authIPs parameter.

  • CVE-2022-38566HigAug 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formEmailTest. This vulnerability allows attackers to cause a Denial of Service (DoS) via the mailname parameter.

  • CVE-2022-38565HigAug 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formEmailTest. This vulnerability allows attackers to cause a Denial of Service (DoS) via the mailpwd parameter.

  • CVE-2022-38564HigAug 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda M3 V1.0.0.12(4856) was discovered to contain a buffer overflow vulnerability in the function formSetPicListItem. This vulnerability allows attackers to cause a Denial of Service (DoS) via the adItemUID parameter.

  • CVE-2022-38563HigAug 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formSetFixTools. This vulnerability allows attackers to cause a Denial of Service (DoS) via the MACAddr parameter.

  • CVE-2022-38562HigAug 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formSetFixTools. This vulnerability allows attackers to cause a Denial of Service (DoS) via the lan parameter.

  • CVE-2022-32043HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formSetAccessCodeInfo.

  • CVE-2022-32041HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formGetPassengerAnalyseData.

  • CVE-2022-32040HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formSetCfm.

  • CVE-2022-32039HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the listN parameter in the function fromDhcpListClient.

  • CVE-2022-32037HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formSetAPCfg.

  • CVE-2022-32036HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda M3 V1.0.0.12 was discovered to contain multiple stack overflow vulnerabilities via the ssidList, storeName, and trademark parameters in the function formSetStoreWeb.

  • CVE-2022-32034HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the items parameter in the function formdelMasteraclist.

  • CVE-2025-15253Dec 30, 2025
    risk 0.00cvss epss 0.01

    A vulnerability has been found in Tenda M3 1.0.0.13(4903). The impacted element is an unknown function of the file /goform/exeCommand. Such manipulation of the argument cmdinput leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been…

  • CVE-2025-15252Dec 30, 2025
    risk 0.00cvss epss 0.03

    A flaw has been found in Tenda M3 1.0.0.13(4903). The affected element is the function formSetRemoteDhcpForAp of the file /goform/setDhcpAP. This manipulation of the argument startip/endip/leasetime/gateway/dns1/dns2 causes stack-based buffer overflow. The attack can be…

  • CVE-2025-15234Dec 30, 2025
    risk 0.00cvss epss 0.02

    A weakness has been identified in Tenda M3 1.0.0.13(4903). Impacted is the function formSetRemoteInternetLanInfo of the file /goform/setInternetLanInfo. This manipulation of the argument portIp/portMask/portGateWay/portDns/portSecDns causes heap-based buffer overflow. It is…

  • CVE-2025-15233Dec 30, 2025
    risk 0.00cvss epss 0.01

    A security flaw has been discovered in Tenda M3 1.0.0.13(4903). This issue affects the function formSetAdInfoDetails of the file /goform/setAdInfoDetail. The manipulation of the argument adName/smsPassword/smsAccount/weixinAccount/weixinName/smsSignature/adRedirectUrl/adCopyRight…