CVE List

CVE-2025-9298

Critical 8.8

A flaw has been found in Tenda M3 1.0.0.12. Affected is the function formQuickIndex of the file /goform/QuickIndex. Executing manipulation of the argument PPPOEPassword can lead to stack-based buffer overflow. The attack can be launched remotely. The exploit has been published and may be used.

Published August 21, 2025.

Affected software

Get alerts for Tenda M3 Firmware

Reference links