Tenda
Tenda G3 Firmware: vulnerabilities and CVEs
Tenda G3 Firmware has 24 published vulnerabilities, 0 of them in the last 12 months. 9 are rated critical and 0 are listed by CISA as actively exploited.
CVEs24
Last 12 months0
Critical9
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-57060 | High (7.5) | 0.49% | — | Sep 9, 2025 | Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the rules parameter in the dns_forward_rule_store function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted… |
| CVE-2025-57078 | High (7.5) | 0.40% | — | Sep 9, 2025 | Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the pppoeServerWhiteMacIndex parameter in the formModifyPppAuthWhiteMac function. This vulnerability allows attackers to cause a Denial of… |
| CVE-2025-57072 | High (7.5) | 0.49% | — | Sep 9, 2025 | Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the staticRouteGateway parameter in the formSetStaticRoute function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a… |
| CVE-2025-57071 | High (7.5) | 0.49% | — | Sep 9, 2025 | Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the vpnUsers parameter in the formAddVpnUsers function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted… |
| CVE-2025-57070 | High (7.5) | 0.49% | — | Sep 9, 2025 | Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the gstUp parameter in the guestWifiRuleRefresh function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted… |
| CVE-2025-57069 | High (7.5) | 0.49% | — | Sep 9, 2025 | Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the pPppUser parameter in the getsinglepppuser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted… |
| CVE-2025-57064 | High (7.5) | 0.49% | — | Sep 9, 2025 | Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the bindDhcpIndex parameter in the modifyDhcpRule function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted… |
| CVE-2025-57063 | High (7.5) | 0.49% | — | Sep 9, 2025 | Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the portMappingIndex parameter in the formDelPortMapping function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a… |
| CVE-2025-57062 | High (7.5) | 0.49% | — | Sep 9, 2025 | Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the delDhcpIndex parameter in the formDelDhcpRule function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted… |
| CVE-2025-57061 | High (7.5) | 0.49% | — | Sep 9, 2025 | Tenda G3 v3.0br_V15.11.0.17 was discovered to contain multiple stack overflows in the formIPMacBindModify function via the ruleId, ip, mac, v6 and remark parameters. This vulnerability allows attackers to cause a Denial… |
| CVE-2025-57059 | High (7.5) | 0.49% | — | Sep 9, 2025 | Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the dhcpIndex parameter in the addDhcpRule function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. |
| CVE-2025-57058 | High (7.5) | 0.49% | — | Sep 9, 2025 | Tenda G3 v3.0br_V15.11.0.17 was discovered to contain multiple stack overflows in the formSetDebugCfg function via the pEnable, pLevel, and pModule parameters. This vulnerability allows attackers to cause a Denial of… |
| CVE-2025-57057 | High (7.5) | 0.49% | — | Sep 9, 2025 | Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the listStr parameter in the ipMacBindListStore function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted… |
| CVE-2024-48192 | High (8) | 0.37% | — | Oct 17, 2024 | Tenda G3 v15.01.0.5(2848_755)_EN was discovered to contain a hardcoded password vulnerability in /etc_ro/shadow, which allows attackers to log in as root |
| CVE-2024-8225 | High (8.7) | 1.2% | — | Aug 27, 2024 | A vulnerability, which was classified as critical, was found in Tenda G3 15.11.0.20. Affected is the function formSetSysTime of the file /goform/SetSysTimeCfg. The manipulation of the argument sysTimePolicy leads to… |
| CVE-2024-4165 | Critical (9.8) | 1.5% | — | Apr 25, 2024 | A vulnerability, which was classified as critical, was found in Tenda G3 15.11.0.17(9502). Affected is the function modifyDhcpRule of the file /goform/modifyDhcpRule. The manipulation of the argument bindDhcpIndex leads… |
| CVE-2024-4164 | Critical (9.8) | 1.5% | — | Apr 25, 2024 | A vulnerability, which was classified as critical, has been found in Tenda G3 15.11.0.17(9502). This issue affects the function formModifyPppAuthWhiteMac of the file /goform/ModifyPppAuthWhiteMac. The manipulation of… |
| CVE-2022-36586 | Critical (9.8) | 0.94% | — | Sep 8, 2022 | In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, there is a buffer overflow vulnerability caused by strcpy in function 0x869f4 in the httpd binary. |
| CVE-2022-36585 | Critical (9.8) | 0.94% | — | Sep 7, 2022 | In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, in httpd binary, the addDhcpRule function has a buffer overflow caused by sscanf. |
| CVE-2022-36587 | Critical (9.8) | 0.94% | — | Sep 7, 2022 | In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, there is a buffer overflow vulnerability caused by sprintf in function in the httpd binary. |
| CVE-2022-36584 | Critical (9.8) | 0.94% | — | Sep 6, 2022 | In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, the getsinglepppuser function has a buffer overflow caused by sscanf. |
| CVE-2021-27707 | Critical (9.8) | 2.8% | — | Apr 14, 2021 | Buffer Overflow in Tenda G1 and G3 routers with firmware v15.11.0.17(9502)_CN allows remote attackers to execute arbitrary code via a crafted action/"portMappingIndex "request. This occurs because the… |
| CVE-2021-27706 | Critical (9.8) | 2.8% | — | Apr 14, 2021 | Buffer Overflow in Tenda G1 and G3 routers with firmware version V15.11.0.17(9502)_CN allows remote attackers to execute arbitrary code via a crafted action/"IPMacBindIndex "request. This occurs because the… |
| CVE-2021-27705 | Critical (9.8) | 2.9% | — | Apr 14, 2021 | Buffer Overflow in Tenda G1 and G3 routers with firmware v15.11.0.17(9502)_CN allows remote attackers to execute arbitrary code via a crafted action/"qosIndex "request. This occurs because the "formQOSRuleDel" function… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.