CVE-2025-15234: Tenda M3 setInternetLanInfo formSetRemoteInternetLanInfo heap-based overflow
A weakness has been identified in Tenda M3 1.0.0.13(4903). Impacted is the function formSetRemoteInternetLanInfo of the file /goform/setInternetLanInfo. This manipulation of the argument portIp/portMask/portGateWay/portDns/portSecDns causes heap-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15234?
CVE-2025-15234 is classified as a high severity vulnerability due to its potential for causing heap-based buffer overflows.
How do I fix CVE-2025-15234?
To mitigate CVE-2025-15234, update the firmware of the Tenda M3 to the latest version provided by the vendor.
Which devices are affected by CVE-2025-15234?
CVE-2025-15234 impacts Tenda M3 devices running firmware version 1.0.0.13(4903).
What type of vulnerability is CVE-2025-15234?
CVE-2025-15234 is a heap-based buffer overflow vulnerability affecting the setInternetLanInfo function.
Can CVE-2025-15234 be exploited remotely?
Yes, CVE-2025-15234 can potentially be exploited remotely due to improper handling of user input.