Home/Product/tenda m3 firmware
Product

tenda m3 firmware

46 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-5567
all versions
A flaw has been found in Tenda M3 1.0.0.10. This vulnerability affects the function setAdvPolicyData of the file /goform/setAdvPol
8.8HIGH
CVE-2025-15253
all versions
A vulnerability has been found in Tenda M3 1.0.0.13(4903). The impacted element is an unknown function of the file /goform/exeComm
8.8HIGH
CVE-2025-15252
all versions
A flaw has been found in Tenda M3 1.0.0.13(4903). The affected element is the function formSetRemoteDhcpForAp of the file /goform/
8.8HIGH
CVE-2025-15234
all versions
A weakness has been identified in Tenda M3 1.0.0.13(4903). Impacted is the function formSetRemoteInternetLanInfo of the file /gofo
8.8HIGH
CVE-2025-15233
all versions
A security flaw has been discovered in Tenda M3 1.0.0.13(4903). This issue affects the function formSetAdInfoDetails of the file /
8.8HIGH
CVE-2025-15232
all versions
A vulnerability was identified in Tenda M3 1.0.0.13(4903). This vulnerability affects the function formSetAdPushInfo of the file /
8.8HIGH
CVE-2025-15231
all versions
A vulnerability was determined in Tenda M3 1.0.0.13(4903). This affects the function formSetRemoteVlanInfo of the file /goform/set
8.8HIGH
CVE-2025-15230
all versions
A vulnerability was found in Tenda M3 1.0.0.13(4903). Affected by this issue is the function formSetVlanPolicy of the file /goform
8.8HIGH
CVE-2025-9299
all versions
A vulnerability has been found in Tenda M3 1.0.0.12. Affected by this vulnerability is the function formGetMasterPassengerAnalyseD
8.8HIGH
CVE-2025-9298
all versions
A flaw has been found in Tenda M3 1.0.0.12. Affected is the function formQuickIndex of the file /goform/QuickIndex. Executing mani
8.8HIGH
CVE-2023-51094
all versions
Tenda M3 V1.0.0.12(4856) was discovered to contain a Command Execution vulnerability via the function TendaTelnet.
9.8CRITICAL
CVE-2023-51093
all versions
Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function fromSetLocalVlanInfo.
9.8CRITICAL
CVE-2023-51092
all versions
Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function upgrade.
9.8CRITICAL
CVE-2023-51091
all versions
Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function R7WebsSecurityHandler.
9.8CRITICAL
CVE-2023-51090
all versions
Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function formGetWeiXinConfig.
9.8CRITICAL
CVE-2023-51095
all versions
Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function formDelWlRfPolicy.
9.8CRITICAL
CVE-2022-38571
all versions
Tenda M3 V1.0.0.12(4856) was discovered to contain a buffer overflow in the function formSetGuideListItem.
7.5HIGH
CVE-2022-38570
all versions
Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow in the function formDelPushedAd. This vulnerability allows att
7.5HIGH
CVE-2022-38569
all versions
Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow in the function formDelAd.
7.5HIGH
CVE-2022-38568
all versions
Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formSetFixTools. This vuln
7.5HIGH
CVE-2022-38567
all versions
Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow vulnerability in the function formSetAdConfigInfo. This vulner
7.5HIGH
CVE-2022-38566
all versions
Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formEmailTest. This vulner
7.5HIGH
CVE-2022-38565
all versions
Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formEmailTest. This vulner
7.5HIGH
CVE-2022-38564
all versions
Tenda M3 V1.0.0.12(4856) was discovered to contain a buffer overflow vulnerability in the function formSetPicListItem. This vulner
7.5HIGH
CVE-2022-38563
all versions
Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formSetFixTools. This vuln
7.5HIGH
CVE-2022-38562
all versions
Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formSetFixTools. This vuln
7.5HIGH
CVE-2022-32043
all versions
Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formSetAccessCodeInfo.
7.5HIGH
CVE-2022-32041
all versions
Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formGetPassengerAnalyseData.
7.5HIGH
CVE-2022-32040
all versions
Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formSetCfm.
7.5HIGH
CVE-2022-32039
all versions
Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the listN parameter in the function fromDhcpListClient.
7.5HIGH
CVE-2022-32037
all versions
Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formSetAPCfg.
7.5HIGH
CVE-2022-32036
all versions
Tenda M3 V1.0.0.12 was discovered to contain multiple stack overflow vulnerabilities via the ssidList, storeName, and trademark pa
7.5HIGH
CVE-2022-32035
all versions
Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formMasterMng.
7.5HIGH
CVE-2022-32034
all versions
Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the items parameter in the function formdelMasteraclist.
7.5HIGH
CVE-2022-27083
all versions
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /cgi-bin/uploadAccessC
9.8CRITICAL
CVE-2022-27082
all versions
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/SetInternetLan
9.8CRITICAL
CVE-2022-27081
all versions
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/SetLanInfo.
9.8CRITICAL
CVE-2022-27080
all versions
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setWorkmode.
9.8CRITICAL
CVE-2022-27079
all versions
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setPicListItem
9.8CRITICAL
CVE-2022-27078
all versions
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setAdInfoDetai
9.8CRITICAL
CVE-2022-27077
all versions
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /cgi-bin/uploadWeiXinP
9.8CRITICAL
CVE-2022-27076
all versions
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/delAd.
9.8CRITICAL
CVE-2022-26536
all versions
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setFixTools.
9.8CRITICAL
CVE-2022-26290
all versions
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/WriteFacMac.
9.8CRITICAL
CVE-2022-26289
all versions
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/exeCommand.
9.8CRITICAL
CVE-2019-11523
all versions
Anviz Global M3 Outdoor RFID Access Control executes any command received from any source. No authentication/encryption is done. A
9.8CRITICAL
threatengine.sh