VendorsTendag3any version
Vulnerabilities

Tenda G3 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

22CVEs
CVE-2021-27705
Buffer Overflow in Tenda G1 and G3 routers with firmware v15.11.0.17(9502)_CN allows remote attackers to execute arbitrary code via a crafted action/"qosIndex "request. This occurs because the "formQOSRuleDel" function directly passes the parameter "qosIndex" to strcpy without limit.
Published 2021-04-14 · Modified
9.8EPSS 0.029
CVE-2021-27706
Buffer Overflow in Tenda G1 and G3 routers with firmware version V15.11.0.17(9502)_CN allows remote attackers to execute arbitrary code via a crafted action/"IPMacBindIndex "request. This occurs because the "formIPMacBindDel" function directly passes the parameter "IPMacBindIndex" to strcpy without limit.
Published 2021-04-14 · Modified
9.8EPSS 0.028
CVE-2021-27707
Buffer Overflow in Tenda G1 and G3 routers with firmware v15.11.0.17(9502)_CN allows remote attackers to execute arbitrary code via a crafted action/"portMappingIndex "request. This occurs because the "formDelPortMapping" function directly passes the parameter "portMappingIndex" to strcpy without limit.
Published 2021-04-14 · Modified
9.8EPSS 0.028
CVE-2024-4164
Tenda G3 ModifyPppAuthWhiteMac formModifyPppAuthWhiteMac stack-based overflow
Published 2024-04-25 · Analyzed
9.8EPSS 0.015
CVE-2024-4165
Tenda G3 modifyDhcpRule stack-based overflow
Published 2024-04-25 · Analyzed
9.8EPSS 0.015
CVE-2024-8225
Tenda G3 SetSysTimeCfg formSetSysTime stack-based overflow
Published 2024-08-27 · Analyzed
9.8EPSS 0.012
CVE-2022-36584
In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, the getsinglepppuser function has a buffer overflow caused by sscanf.
Published 2022-09-06 · Modified
9.8EPSS 0.009
CVE-2022-36585
In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, in httpd binary, the addDhcpRule function has a buffer overflow caused by sscanf.
Published 2022-09-07 · Modified
9.8EPSS 0.009
CVE-2022-36586
In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, there is a buffer overflow vulnerability caused by strcpy in function 0x869f4 in the httpd binary.
Published 2022-09-07 · Modified
9.8EPSS 0.009
CVE-2022-36587
In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, there is a buffer overflow vulnerability caused by sprintf in function in the httpd binary.
Published 2022-09-07 · Modified
9.8EPSS 0.009
CVE-2024-48192
Tenda G3 v15.01.0.5(2848_755)_EN was discovered to contain a hardcoded password vulnerability in /etc_ro/shadow, which allows attackers to log in as root
Published 2024-10-17 · Analyzed
8.0EPSS 0.004
CVE-2025-57072
Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the staticRouteGateway parameter in the formSetStaticRoute function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
Published 2025-09-09 · Analyzed
7.5EPSS 0.005
CVE-2025-57071
Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the vpnUsers parameter in the formAddVpnUsers function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
Published 2025-09-09 · Analyzed
7.5EPSS 0.005
CVE-2025-57070
Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the gstUp parameter in the guestWifiRuleRefresh function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
Published 2025-09-09 · Analyzed
7.5EPSS 0.005
CVE-2025-57069
Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the pPppUser parameter in the getsinglepppuser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
Published 2025-09-09 · Analyzed
7.5EPSS 0.005
CVE-2025-57064
Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the bindDhcpIndex parameter in the modifyDhcpRule function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
Published 2025-09-09 · Analyzed
7.5EPSS 0.005
CVE-2025-57063
Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the portMappingIndex parameter in the formDelPortMapping function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
Published 2025-09-09 · Analyzed
7.5EPSS 0.005
CVE-2025-57062
Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the delDhcpIndex parameter in the formDelDhcpRule function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
Published 2025-09-09 · Analyzed
7.5EPSS 0.005
CVE-2025-57061
Tenda G3 v3.0br_V15.11.0.17 was discovered to contain multiple stack overflows in the formIPMacBindModify function via the ruleId, ip, mac, v6 and remark parameters. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
Published 2025-09-09 · Analyzed
7.5EPSS 0.005
CVE-2025-57059
Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the dhcpIndex parameter in the addDhcpRule function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
Published 2025-09-09 · Analyzed
7.5EPSS 0.005
CVE-2025-57058
Tenda G3 v3.0br_V15.11.0.17 was discovered to contain multiple stack overflows in the formSetDebugCfg function via the pEnable, pLevel, and pModule parameters. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
Published 2025-09-09 · Analyzed
7.5EPSS 0.005
CVE-2025-57057
Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the listStr parameter in the ipMacBindListStore function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
Published 2025-09-09 · Analyzed
7.5EPSS 0.005