CVE-2025-15230: Tenda M3 setVlanPolicyData formSetVlanPolicy heap-based overflow
A vulnerability was found in Tenda M3 1.0.0.13(4903). Affected by this issue is the function formSetVlanPolicy of the file /goform/setVlanPolicyData. Performing a manipulation of the argument qvlantruckport results in heap-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15230?
CVE-2025-15230 is classified as a high severity vulnerability due to its impact on system stability through heap-based buffer overflow.
How do I fix CVE-2025-15230?
To mitigate CVE-2025-15230, update the Tenda M3 firmware to the latest version provided by the manufacturer.
What systems are affected by CVE-2025-15230?
CVE-2025-15230 affects the Tenda M3 router running the firmware version 1.0.0.13(4903).
What type of vulnerability is CVE-2025-15230?
CVE-2025-15230 is a heap-based buffer overflow vulnerability that can be exploited remotely.
Can CVE-2025-15230 be exploited remotely?
Yes, CVE-2025-15230 allows for remote exploitation if the vulnerability is not patched.