CVE-2025-65804: Medium severity Tenda AX3 vulnerability
Published Dec 8, 2025
·Updated
Tenda AX3 v16.03.12.11 contains a stack overflow in formSetIptv via the iptvType parameter, which can cause memory corruption and enable remote code execution (RCE).
Affected Software
3 affected components
Tenda AX3
All of the following
Tenda AX3 firmware=16.03.12.11
Tenda AX3
Event History
Dec 8, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-65804?
CVE-2025-65804 is rated as critical due to its potential for remote code execution caused by a stack overflow.
2
How do I fix CVE-2025-65804?
To mitigate CVE-2025-65804, it is recommended to update Tenda AX3 to the latest firmware version provided by the vendor.
3
What does CVE-2025-65804 exploit in Tenda AX3?
CVE-2025-65804 exploits a stack overflow vulnerability in the formSetIptv function via the iptvType parameter.
4
Can CVE-2025-65804 lead to remote code execution?
Yes, CVE-2025-65804 can lead to remote code execution due to memory corruption following an attack.
5
Which devices are affected by CVE-2025-65804?
CVE-2025-65804 specifically affects the Tenda AX3 router models running firmware version v16.03.12.11.