Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-9765 | A vulnerability, which was classified as critical, has been found in Tenda RX3 16.03.13.11. This issue affects the function formSetDeviceName of the file /goform/SetOnlineDevName. The manipulation of the argument devName leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. |
Mon, 07 Apr 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tenda
Tenda rx3 Tenda rx3 Firmware |
|
| Weaknesses | CWE-787 | |
| CPEs | cpe:2.3:h:tenda:rx3:-:*:*:*:*:*:*:* cpe:2.3:o:tenda:rx3_firmware:16.03.13.11_multi:*:*:*:*:*:*:* |
|
| Vendors & Products |
Tenda
Tenda rx3 Tenda rx3 Firmware |
Fri, 04 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
ssvc
|
Fri, 04 Apr 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability, which was classified as critical, has been found in Tenda RX3 16.03.13.11. This issue affects the function formSetDeviceName of the file /goform/SetOnlineDevName. The manipulation of the argument devName leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Title | Tenda RX3 SetOnlineDevName formSetDeviceName stack-based overflow | |
| Weaknesses | CWE-119 CWE-121 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-04-04T18:55:17.132Z
Reserved: 2025-04-04T07:46:47.401Z
Link: CVE-2025-3259
Updated: 2025-04-04T18:55:05.719Z
Status : Analyzed
Published: 2025-04-04T18:15:49.137
Modified: 2025-04-07T18:19:20.090
Link: CVE-2025-3259
No data.
OpenCVE Enrichment
No data.
EUVD