Tenda
Tenda M3 Firmware: vulnerabilidades y CVE
Tenda M3 Firmware tiene 45 vulnerabilidades publicadas, 8 de ellas en los últimos 12 meses. 17 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE45
Últimos 12 meses8
Críticas17
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-5567 | Alta (7.4) | 1.0% | — | 5 abr 2026 | A flaw has been found in Tenda M3 1.0.0.10. This vulnerability affects the function setAdvPolicyData of the file /goform/setAdvPolicyData of the component Destination Handler. Executing a manipulation of the argument… |
| CVE-2025-15253 | Alta (7.4) | 0.74% | — | 30 dic 2025 | A vulnerability has been found in Tenda M3 1.0.0.13(4903). The impacted element is an unknown function of the file /goform/exeCommand. Such manipulation of the argument cmdinput leads to stack-based buffer overflow. The… |
| CVE-2025-15252 | Alta (7.4) | 3.3% | — | 30 dic 2025 | A flaw has been found in Tenda M3 1.0.0.13(4903). The affected element is the function formSetRemoteDhcpForAp of the file /goform/setDhcpAP. This manipulation of the argument startip/endip/leasetime/gateway/dns1/dns2… |
| CVE-2025-15234 | Alta (7.4) | 2.9% | — | 30 dic 2025 | A weakness has been identified in Tenda M3 1.0.0.13(4903). Impacted is the function formSetRemoteInternetLanInfo of the file /goform/setInternetLanInfo. This manipulation of the argument… |
| CVE-2025-15233 | Alta (7.4) | 0.74% | — | 30 dic 2025 | A security flaw has been discovered in Tenda M3 1.0.0.13(4903). This issue affects the function formSetAdInfoDetails of the file /goform/setAdInfoDetail. The manipulation of the argument… |
| CVE-2025-15232 | Alta (7.4) | 0.74% | — | 30 dic 2025 | A vulnerability was identified in Tenda M3 1.0.0.13(4903). This vulnerability affects the function formSetAdPushInfo of the file /goform/setAdPushInfo. The manipulation of the argument mac/terminal leads to stack-based… |
| CVE-2025-15231 | Alta (7.4) | 0.74% | — | 30 dic 2025 | A vulnerability was determined in Tenda M3 1.0.0.13(4903). This affects the function formSetRemoteVlanInfo of the file /goform/setVlanInfo. Executing a manipulation of the argument ID/vlan/port can lead to stack-based… |
| CVE-2025-15230 | Alta (7.4) | 0.74% | — | 30 dic 2025 | A vulnerability was found in Tenda M3 1.0.0.13(4903). Affected by this issue is the function formSetVlanPolicy of the file /goform/setVlanPolicyData. Performing a manipulation of the argument qvlan_truck_port results in… |
| CVE-2025-9299 | Alta (7.4) | 5.1% | — | 21 ago 2025 | A vulnerability has been found in Tenda M3 1.0.0.12. Affected by this vulnerability is the function formGetMasterPassengerAnalyseData of the file /goform/getMasterPassengerAnalyseData. The manipulation of the argument… |
| CVE-2025-9298 | Alta (7.4) | 1.1% | — | 21 ago 2025 | A flaw has been found in Tenda M3 1.0.0.12. Affected is the function formQuickIndex of the file /goform/QuickIndex. Executing manipulation of the argument PPPOEPassword can lead to stack-based buffer overflow. The… |
| CVE-2023-51094 | Crítica (9.8) | 1.1% | — | 26 dic 2023 | Tenda M3 V1.0.0.12(4856) was discovered to contain a Command Execution vulnerability via the function TendaTelnet. |
| CVE-2023-51093 | Crítica (9.8) | 0.84% | — | 26 dic 2023 | Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function fromSetLocalVlanInfo. |
| CVE-2023-51092 | Crítica (9.8) | 13% | — | 26 dic 2023 | Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function upgrade. |
| CVE-2023-51091 | Crítica (9.8) | 8.5% | — | 26 dic 2023 | Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function R7WebsSecurityHandler. |
| CVE-2023-51090 | Crítica (9.8) | 0.70% | — | 26 dic 2023 | Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function formGetWeiXinConfig. |
| CVE-2023-51095 | Crítica (9.8) | 0.76% | — | 26 dic 2023 | Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function formDelWlRfPolicy. |
| CVE-2022-38571 | Alta (7.5) | 0.97% | — | 28 ago 2022 | Tenda M3 V1.0.0.12(4856) was discovered to contain a buffer overflow in the function formSetGuideListItem. |
| CVE-2022-38570 | Alta (7.5) | 0.97% | — | 28 ago 2022 | Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow in the function formDelPushedAd. This vulnerability allows attackers to cause a Denial of Service (DoS) via the adPushUID parameter. |
| CVE-2022-38569 | Alta (7.5) | 0.97% | — | 28 ago 2022 | Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow in the function formDelAd. |
| CVE-2022-38568 | Alta (7.5) | 0.97% | — | 28 ago 2022 | Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formSetFixTools. This vulnerability allows attackers to cause a Denial of Service (DoS) via the hostname parameter. |
| CVE-2022-38567 | Alta (7.5) | 0.97% | — | 28 ago 2022 | Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow vulnerability in the function formSetAdConfigInfo. This vulnerability allows attackers to cause a Denial of Service (DoS) via the authIPs parameter. |
| CVE-2022-38566 | Alta (7.5) | 0.97% | — | 28 ago 2022 | Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formEmailTest. This vulnerability allows attackers to cause a Denial of Service (DoS) via the mailname parameter. |
| CVE-2022-38565 | Alta (7.5) | 0.97% | — | 28 ago 2022 | Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formEmailTest. This vulnerability allows attackers to cause a Denial of Service (DoS) via the mailpwd parameter. |
| CVE-2022-38564 | Alta (7.5) | 0.97% | — | 28 ago 2022 | Tenda M3 V1.0.0.12(4856) was discovered to contain a buffer overflow vulnerability in the function formSetPicListItem. This vulnerability allows attackers to cause a Denial of Service (DoS) via the adItemUID parameter. |
| CVE-2022-38563 | Alta (7.5) | 0.97% | — | 28 ago 2022 | Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formSetFixTools. This vulnerability allows attackers to cause a Denial of Service (DoS) via the MACAddr parameter. |
| CVE-2022-38562 | Alta (7.5) | 0.97% | — | 28 ago 2022 | Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formSetFixTools. This vulnerability allows attackers to cause a Denial of Service (DoS) via the lan parameter. |
| CVE-2022-32043 | Alta (7.5) | 1.1% | — | 1 jul 2022 | Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formSetAccessCodeInfo. |
| CVE-2022-32041 | Alta (7.5) | 1.1% | — | 1 jul 2022 | Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formGetPassengerAnalyseData. |
| CVE-2022-32040 | Alta (7.5) | 1.1% | — | 1 jul 2022 | Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formSetCfm. |
| CVE-2022-32039 | Alta (7.5) | 1.1% | — | 1 jul 2022 | Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the listN parameter in the function fromDhcpListClient. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.