ID

VAR-202509-1119


CVE

CVE-2025-57071


TITLE

Tenda G3 formAddVpnUsers function buffer overflow vulnerability

Trust: 0.6

sources: CNVD: CNVD-2025-21163

DESCRIPTION

Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the vpnUsers parameter in the formAddVpnUsers function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. The Tenda G3 is a QoS VPN router from the Chinese company Tenda. This vulnerability stems from the failure to properly validate the length of the input data in the vpnUsers parameter in the formAddVpnUsers function

Trust: 1.44

sources: NVD: CVE-2025-57071 // CNVD: CNVD-2025-21163

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2025-21163

AFFECTED PRODUCTS

vendor:tendamodel:g3 v3.0br v15.11.0.17scope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2025-21163

CVSS

SEVERITY

CVSSV2

CVSSV3

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2025-57071
value: HIGH

Trust: 1.0

CNVD: CNVD-2025-21163
value: HIGH

Trust: 0.6

CNVD: CNVD-2025-21163
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2025-57071
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.1

Trust: 1.0

sources: CNVD: CNVD-2025-21163 // NVD: CVE-2025-57071

PROBLEMTYPE DATA

problemtype:CWE-121

Trust: 1.0

sources: NVD: CVE-2025-57071

EXTERNAL IDS

db:NVDid:CVE-2025-57071

Trust: 1.6

db:CNVDid:CNVD-2025-21163

Trust: 0.6

sources: CNVD: CNVD-2025-21163 // NVD: CVE-2025-57071

REFERENCES

url:https://github.com/vulndetailrecord/vulfordevice/blob/main/tenda/g3/formaddvpnusers.md

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2025-57071

Trust: 0.6

sources: CNVD: CNVD-2025-21163 // NVD: CVE-2025-57071

SOURCES

db:CNVDid:CNVD-2025-21163
db:NVDid:CVE-2025-57071

LAST UPDATE DATE

2025-09-13T23:14:03.648000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2025-21163date:2025-09-12T00:00:00
db:NVDid:CVE-2025-57071date:2025-09-11T17:14:25.240

SOURCES RELEASE DATE

db:CNVDid:CNVD-2025-21163date:2025-09-12T00:00:00
db:NVDid:CVE-2025-57071date:2025-09-09T17:16:09.797