CVE-2025-69766

CRITICAL

Tenda AX3 Firmware 16.03.12.11 - Stack-based Buffer Overflow in formGetIptv

Title source: llm
STIX 2.1

Description

Tenda AX3 firmware v16.03.12.11 contains a stack-based buffer overflow in the formGetIptv function due to improper handling of the citytag stack buffer, which may result in memory corruption and remote code execution.

Scores

CVSS v3 9.8
EPSS 0.0059
EPSS Percentile 69.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-121
Status published
Products (1)
tenda/ax3_firmware 16.03.12.11
Published Jan 21, 2026
Tracked Since Feb 18, 2026