CVE-2025-15231: Tenda M3 setVlanInfo formSetRemoteVlanInfo stack-based overflow
A vulnerability was determined in Tenda M3 1.0.0.13(4903). This affects the function formSetRemoteVlanInfo of the file /goform/setVlanInfo. Executing a manipulation of the argument ID/vlan/port can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15231?
CVE-2025-15231 is classified as a critical vulnerability due to its potential for remote exploitation and causing a stack-based buffer overflow.
How do I fix CVE-2025-15231?
To mitigate CVE-2025-15231, ensure the Tenda M3 firmware is updated to the latest version that addresses this vulnerability.
Who is affected by CVE-2025-15231?
CVE-2025-15231 specifically affects users of Tenda M3 devices running firmware version 1.0.0.13 (4903).
What type of attack is possible with CVE-2025-15231?
CVE-2025-15231 allows an attacker to execute a remote stack-based buffer overflow by manipulating specific arguments in the setVlanInfo function.
Can CVE-2025-15231 be exploited locally?
CVE-2025-15231 is a remote vulnerability, meaning it can be exploited without physical access to the affected Tenda M3 device.