VendorsTendaax3_firmware16.03.12.11
Vulnerabilities

Tenda ax3 Firmware 16.03.12.11

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2023-27240
Tenda AX3 V16.03.12.11 was discovered to contain a command injection vulnerability via the lanip parameter at /goform/AdvSetLanip.
Published 2023-03-15 · Modified
9.8EPSS 0.028
CVE-2023-49409
Tenda AX3 V16.03.12.11 was discovered to contain a Command Execution vulnerability via the function /goform/telnet.
Published 2023-12-07 · Modified
9.8EPSS 0.015
CVE-2025-69764
Tenda AX3 firmware v16.03.12.11 contains a stack-based buffer overflow in the formGetIptv function due to improper handling of the stbpvid stack buffer, which may result in memory corruption and remote code execution.
Published 2026-01-22 · Analyzed
9.8EPSS 0.011
CVE-2023-24212
Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the timeType function at /goform/SetSysTimeCfg.
Published 2023-02-23 · Modified
9.8EPSS 0.011
CVE-2023-51812
Tenda AX3 v16.03.12.11 was discovered to contain a remote code execution (RCE) vulnerability via the list parameter at /goform/SetNetControlList.
Published 2024-01-04 · Modified
9.8EPSS 0.011
CVE-2023-49408
Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the function set_device_name.
Published 2023-12-07 · Modified
9.8EPSS 0.009
CVE-2025-69762
Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formSetIptv via the list parameter, which can cause memory corruption and enable remote code execution.
Published 2026-01-21 · Analyzed
9.8EPSS 0.009
CVE-2025-69763
Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formSetIptv via the vlanId parameter, which can cause memory corruption and enable remote code execution.
Published 2026-01-21 · Analyzed
9.8EPSS 0.009
CVE-2023-27239
Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the shareSpeed parameter at /goform/WifiGuestSet.
Published 2023-03-15 · Modified
9.8EPSS 0.008
CVE-2025-69766
Tenda AX3 firmware v16.03.12.11 contains a stack-based buffer overflow in the formGetIptv function due to improper handling of the citytag stack buffer, which may result in memory corruption and remote code execution.
Published 2026-01-21 · Analyzed
9.8EPSS 0.008
CVE-2023-27042
Tenda AX3 V16.03.12.11 is vulnerable to Buffer Overflow via /goform/SetFirewallCfg.
Published 2023-03-24 · Modified
8.8EPSS 0.009
CVE-2023-47422
An access control issue in /usr/sbin/httpd in Tenda TX9 V1 V22.03.02.54, Tenda AX3 V3 V16.03.12.11, Tenda AX9 V1 V22.03.01.46, and Tenda AX12 V1 V22.03.01.46 allows attackers to bypass authentication on any endpoint via a crafted URL.
Published 2024-02-20 · Analyzed
8.8EPSS 0.005
CVE-2023-40915
Tenda AX3 v16.03.12.11 has a stack buffer overflow vulnerability detected at function form_fast_setting_wifi_set. This vulnerability allows attackers to cause a Denial of Service (DoS) via the ssid parameter.
Published 2023-08-25 · Modified
7.5EPSS 0.007
CVE-2025-69765
Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formGetIptv function and the list parameter, which can cause memory corruption and enable remote code execution.
Published 2026-03-03 · Analyzed
7.5EPSS 0.007
CVE-2025-65804
Tenda AX3 v16.03.12.11 contains a stack overflow in formSetIptv via the iptvType parameter, which can cause memory corruption and enable remote code execution (RCE).
Published 2025-12-08 · Analyzed
6.5EPSS 0.005