CVE-2025-15252: Tenda M3 setDhcpAP formSetRemoteDhcpForAp stack-based overflow
A flaw has been found in Tenda M3 1.0.0.13(4903). The affected element is the function formSetRemoteDhcpForAp of the file /goform/setDhcpAP. This manipulation of the argument startip/endip/leasetime/gateway/dns1/dns2 causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15252?
CVE-2025-15252 is classified as a high severity vulnerability due to the potential for stack-based buffer overflow.
How do I fix CVE-2025-15252?
To mitigate CVE-2025-15252, update the Tenda M3 firmware to the latest version provided by the vendor.
What devices are affected by CVE-2025-15252?
CVE-2025-15252 affects the Tenda M3 device running firmware version 1.0.0.13.
What type of vulnerability is CVE-2025-15252?
CVE-2025-15252 is a stack-based buffer overflow vulnerability.
Can CVE-2025-15252 be exploited remotely?
Yes, CVE-2025-15252 can be exploited remotely through manipulation of specific arguments.