📦 Ax3 Firmware

by Tenda

🔍 What is Ax3 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-69764

CRITICAL CVSS 9.8 Jan 22, 2026

This vulnerability allows remote attackers to execute arbitrary code on Tenda AX3 routers by exploiting a stack-based buffer overflow in the formGetIptv function. Attackers can send specially crafted ...

CVE-2025-69762

CRITICAL CVSS 9.8 Jan 21, 2026

This vulnerability allows remote attackers to execute arbitrary code on Tenda AX3 routers by exploiting a stack overflow in the formSetIptv function. Attackers can send specially crafted requests to t...

CVE-2025-69763

CRITICAL CVSS 9.8 Jan 21, 2026

This vulnerability allows remote attackers to execute arbitrary code on Tenda AX3 routers by exploiting a stack overflow in the formSetIptv function via the vlanId parameter. Attackers can achieve ful...

CVE-2025-69766

CRITICAL CVSS 9.8 Jan 21, 2026

This vulnerability allows remote attackers to execute arbitrary code on Tenda AX3 routers by exploiting a stack-based buffer overflow in the formGetIptv function. Attackers can achieve full system com...

CVE-2023-27239

CRITICAL CVSS 9.8 Mar 15, 2023

CVE-2023-27239 is a critical stack overflow vulnerability in Tenda AX3 routers that allows remote attackers to execute arbitrary code by sending specially crafted requests to the /goform/WifiGuestSet ...

CVE-2023-24212

CRITICAL CVSS 9.8 Feb 23, 2023

CVE-2023-24212 is a critical stack overflow vulnerability in Tenda AX3 routers that allows remote attackers to execute arbitrary code or cause denial of service by sending specially crafted requests t...

CVE-2022-24995

CRITICAL CVSS 9.8 Mar 10, 2022

This vulnerability is a stack overflow in Tenda AX3 routers running firmware version 16.03.12.10_CN. Attackers can send specially crafted time parameters to cause a Denial of Service (DoS), potentiall...

CVE-2021-46393

CRITICAL CVSS 9.8 Mar 4, 2022

This CVE describes a critical stack buffer overflow vulnerability in Tenda-AX3 routers that allows remote code execution. Attackers can exploit it by sending specially crafted HTTP POST requests to th...

CVE-2022-24148

CRITICAL CVSS 9.8 Feb 4, 2022

CVE-2022-24148 is a critical command injection vulnerability in Tenda AX3 routers that allows attackers to execute arbitrary system commands via the dmzIp parameter in the mDMZSetCfg function. This af...

CVE-2022-24150

CRITICAL CVSS 9.8 Feb 4, 2022

This vulnerability allows remote attackers to execute arbitrary commands on Tenda AX3 routers via command injection in the remoteIp parameter. Attackers can gain full control of affected devices, pote...

CVE-2022-24144

CRITICAL CVSS 9.8 Feb 4, 2022

CVE-2022-24144 is a critical command injection vulnerability in Tenda AX3 routers that allows attackers to execute arbitrary system commands by manipulating gateway, dns1, and dns2 parameters. This af...

CVE-2025-63149

HIGH CVSS 7.5 Nov 10, 2025

This CVE describes a stack overflow vulnerability in Tenda AX3 routers running firmware version V16.03.12.10_CN. Attackers can exploit this by sending specially crafted requests to the urls parameter ...

CVE-2025-55603

HIGH CVSS 7.5 Aug 22, 2025

A buffer overflow vulnerability exists in Tenda AX3 routers running firmware version V16.03.12.10_CN. Attackers can exploit this by sending specially crafted NTP server parameters to the fromSetSysTim...

CVE-2025-55606

HIGH CVSS 7.5 Aug 22, 2025

This CVE describes a buffer overflow vulnerability in Tenda AX3 routers running firmware version V16.03.12.10_CN. Attackers can exploit this by sending specially crafted requests to the serverName par...

CVE-2023-40915

HIGH CVSS 7.5 Aug 25, 2023

This vulnerability in Tenda AX3 routers allows attackers to trigger a stack buffer overflow via the ssid parameter in the form_fast_setting_wifi_set function, leading to Denial of Service (DoS). Attac...

CVE-2023-27042

HIGH CVSS 8.8 Mar 24, 2023

CVE-2023-27042 is a buffer overflow vulnerability in Tenda AX3 routers that allows remote attackers to execute arbitrary code or cause denial of service via the /goform/SetFirewallCfg endpoint. This a...

CVE-2022-24152

HIGH CVSS 7.5 Feb 4, 2022

CVE-2022-24152 is a stack overflow vulnerability in Tenda AX3 routers running firmware version 16.03.12.10_CN. Attackers can exploit this by sending specially crafted requests to the fromSetRouteStati...

CVE-2022-24154

HIGH CVSS 7.5 Feb 4, 2022

This vulnerability is a stack overflow in Tenda AX3 routers running firmware version 16.03.12.10_CN. Attackers can send specially crafted rebootTime parameter to the formSetRebootTimer function, causi...

CVE-2022-24156

HIGH CVSS 7.5 Feb 4, 2022

CVE-2022-24156 is a stack overflow vulnerability in Tenda AX3 routers running firmware version 16.03.12.10_CN. Attackers can exploit this by sending specially crafted requests to the formSetVirtualSer...

CVE-2022-24158

HIGH CVSS 7.5 Feb 4, 2022

CVE-2022-24158 is a stack overflow vulnerability in Tenda AX3 routers running firmware version 16.03.12.10_CN. Attackers can exploit this by sending specially crafted requests to the fromSetIpMacBind ...

CVE-2022-24160

HIGH CVSS 7.5 Feb 4, 2022

CVE-2022-24160 is a stack overflow vulnerability in Tenda AX3 routers that allows attackers to cause Denial of Service (DoS) by sending specially crafted requests to the devName parameter. This affect...

CVE-2022-24162

HIGH CVSS 7.5 Feb 4, 2022

CVE-2022-24162 is a stack overflow vulnerability in Tenda AX3 routers running firmware version 16.03.12.10_CN. Attackers can exploit this by sending specially crafted requests to the saveParentControl...

CVE-2022-24143

HIGH CVSS 7.5 Feb 4, 2022

This CVE describes a stack overflow vulnerability in Tenda AX3 and AX12 routers' form_fast_setting_wifi_set function. Attackers can exploit it by sending specially crafted timeZone parameter values to...

CVE-2022-24146

HIGH CVSS 7.5 Feb 4, 2022

Tenda AX3 routers running firmware version 16.03.12.10_CN contain a stack overflow vulnerability in the formSetQosBand function. Attackers can exploit this by sending specially crafted requests to the...

CVE-2025-65804

MEDIUM CVSS 6.5 Dec 8, 2025

This CVE describes a stack overflow vulnerability in Tenda AX3 routers that allows remote attackers to execute arbitrary code by sending specially crafted requests to the formSetIptv endpoint. The vul...