📦 M3 Firmware

by Tenda

🔍 What is M3 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-51090

CRITICAL CVSS 9.8 Dec 26, 2023

CVE-2023-51090 is a critical stack overflow vulnerability in Tenda M3 routers that allows remote attackers to execute arbitrary code by sending specially crafted requests to the formGetWeiXinConfig fu...

CVE-2023-51092

CRITICAL CVSS 9.8 Dec 26, 2023

This CVE describes a stack overflow vulnerability in Tenda M3 routers that allows remote attackers to execute arbitrary code via the upgrade function. Attackers can exploit this to gain full control o...

CVE-2023-51094

CRITICAL CVSS 9.8 Dec 26, 2023

Tenda M3 routers running firmware version 1.0.0.12(4856) contain a command injection vulnerability in the TendaTelnet function. This allows remote attackers to execute arbitrary commands with root pri...

CVE-2023-51095

CRITICAL CVSS 9.8 Dec 26, 2023

Tenda M3 routers running firmware version 1.0.0.12(4856) contain a stack-based buffer overflow vulnerability in the formDelWlRfPolicy function. This allows remote attackers to execute arbitrary code o...

CVE-2022-26290

CRITICAL CVSS 9.8 Mar 24, 2022

CVE-2022-26290 is a command injection vulnerability in Tenda M3 routers that allows attackers to execute arbitrary commands on the device. This affects Tenda M3 router users running vulnerable firmwar...

CVE-2022-27076

CRITICAL CVSS 9.8 Mar 24, 2022

CVE-2022-27076 is a command injection vulnerability in Tenda M3 routers that allows attackers to execute arbitrary commands on the device. This affects Tenda M3 router users running vulnerable firmwar...

CVE-2022-27078

CRITICAL CVSS 9.8 Mar 24, 2022

This CVE describes a command injection vulnerability in Tenda M3 routers that allows attackers to execute arbitrary commands on the device. The vulnerability exists in the /goform/setAdInfoDetail comp...

CVE-2022-27080

CRITICAL CVSS 9.8 Mar 24, 2022

CVE-2022-27080 is a command injection vulnerability in Tenda M3 routers that allows attackers to execute arbitrary commands on the device. This affects Tenda M3 routers running firmware version 1.10 V...

CVE-2022-27082

CRITICAL CVSS 9.8 Mar 24, 2022

CVE-2022-27082 is a command injection vulnerability in Tenda M3 routers that allows attackers to execute arbitrary commands on the device. This affects Tenda M3 router users running vulnerable firmwar...

CVE-2025-15234

HIGH CVSS 8.8 Dec 30, 2025

This CVE describes a heap-based buffer overflow vulnerability in Tenda M3 routers version 1.0.0.13(4903). Attackers can remotely exploit this vulnerability by sending specially crafted requests to the...

CVE-2025-15232

HIGH CVSS 8.8 Dec 30, 2025

A stack-based buffer overflow vulnerability in Tenda M3 routers allows remote attackers to execute arbitrary code by manipulating the mac/terminal parameter in the formSetAdPushInfo function. This aff...

CVE-2025-15233

HIGH CVSS 8.8 Dec 30, 2025

This vulnerability allows remote attackers to execute arbitrary code on Tenda M3 routers via a heap-based buffer overflow in the web interface. Attackers can exploit this by sending specially crafted ...

CVE-2025-15231

HIGH CVSS 8.8 Dec 30, 2025

This vulnerability allows remote attackers to execute arbitrary code on Tenda M3 routers via a stack-based buffer overflow in the formSetRemoteVlanInfo function. Attackers can exploit this by manipula...

CVE-2025-15230

HIGH CVSS 8.8 Dec 30, 2025

This vulnerability allows remote attackers to execute arbitrary code on Tenda M3 routers via a heap-based buffer overflow in the formSetVlanPolicy function. Attackers can exploit this without authenti...

CVE-2025-9299

HIGH CVSS 8.8 Aug 21, 2025

A stack-based buffer overflow vulnerability in Tenda M3 routers allows remote attackers to execute arbitrary code by manipulating the 'Time' parameter in the formGetMasterPassengerAnalyseData function...