CVE-2025-9298: Tenda M3 QuickIndex formQuickIndex stack-based overflow
A flaw has been found in Tenda M3 1.0.0.12. Affected is the function formQuickIndex of the file /goform/QuickIndex. Executing manipulation of the argument PPPOEPassword can lead to stack-based buffer overflow. The attack can be launched remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9298?
CVE-2025-9298 is classified as a high severity vulnerability due to the potential for remote exploitation leading to stack-based buffer overflow.
How do I fix CVE-2025-9298?
To fix CVE-2025-9298, users should update their Tenda M3 router firmware to the latest version provided by the vendor.
What devices are affected by CVE-2025-9298?
CVE-2025-9298 specifically affects the Tenda M3 model with version 1.0.0.12.
Can CVE-2025-9298 be exploited remotely?
Yes, CVE-2025-9298 can be exploited remotely, allowing attackers to manipulate the PPPOEPassword argument.
What is the impact of CVE-2025-9298?
The impact of CVE-2025-9298 includes potential unauthorized access to the device and execution of arbitrary code due to buffer overflow.