CVE-2025-15253: Tenda M3 exeCommand stack-based overflow
A vulnerability has been found in Tenda M3 1.0.0.13(4903). The impacted element is an unknown function of the file /goform/exeCommand. Such manipulation of the argument cmdinput leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15253?
CVE-2025-15253 is considered a high severity vulnerability due to its potential for remote exploitation leading to stack-based buffer overflow.
How do I fix CVE-2025-15253?
To fix CVE-2025-15253, update your Tenda M3 device to the latest firmware version that addresses this vulnerability.
What type of vulnerability is CVE-2025-15253?
CVE-2025-15253 is classified as a stack-based buffer overflow vulnerability.
Can CVE-2025-15253 be exploited remotely?
Yes, CVE-2025-15253 can be exploited remotely, making it critical for affected users to take immediate action.
Which software is affected by CVE-2025-15253?
CVE-2025-15253 affects the Tenda M3 version 1.0.0.13(4903).