ID

VAR-202509-1341


CVE

CVE-2025-57062


TITLE

Shenzhen Tenda Technology Co.,Ltd.  of  G3  Stack-based buffer overflow vulnerability in firmware

Trust: 0.8

sources: JVNDB: JVNDB-2025-014168

DESCRIPTION

Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the delDhcpIndex parameter in the formDelDhcpRule function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. Shenzhen Tenda Technology Co.,Ltd. of G3 A stack-based buffer overflow vulnerability exists in the firmware.Service operation interruption (DoS) It may be in a state. The Tenda G3 is a QoS VPN router from the Chinese company Tenda. This vulnerability stems from the fact that the delDhcpIndex parameter in the formDelDhcpRule function fails to properly validate the length of input data

Trust: 2.16

sources: NVD: CVE-2025-57062 // JVNDB: JVNDB-2025-014168 // CNVD: CNVD-2025-21164

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2025-21164

AFFECTED PRODUCTS

vendor:tendamodel:g3scope:lteversion:15.11.0.17\(9502\)

Trust: 1.0

vendor:tendamodel:g3scope: - version: -

Trust: 0.8

vendor:tendamodel:g3scope:lteversion:g3 firmware 15.11.0.17(9502) and earlier

Trust: 0.8

vendor:tendamodel:g3scope:eqversion: -

Trust: 0.8

vendor:tendamodel:g3 v3.0br v15.11.0.17scope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2025-21164 // JVNDB: JVNDB-2025-014168 // NVD: CVE-2025-57062

CVSS

SEVERITY

CVSSV2

CVSSV3

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2025-57062
value: HIGH

Trust: 1.0

OTHER: JVNDB-2025-014168
value: HIGH

Trust: 0.8

CNVD: CNVD-2025-21164
value: HIGH

Trust: 0.6

CNVD: CNVD-2025-21164
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2025-57062
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.1

Trust: 1.0

OTHER: JVNDB-2025-014168
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2025-21164 // JVNDB: JVNDB-2025-014168 // NVD: CVE-2025-57062

PROBLEMTYPE DATA

problemtype:CWE-121

Trust: 1.0

problemtype:Stack-based buffer overflow (CWE-121) [ others ]

Trust: 0.8

sources: JVNDB: JVNDB-2025-014168 // NVD: CVE-2025-57062

EXTERNAL IDS

db:NVDid:CVE-2025-57062

Trust: 3.2

db:JVNDBid:JVNDB-2025-014168

Trust: 0.8

db:CNVDid:CNVD-2025-21164

Trust: 0.6

sources: CNVD: CNVD-2025-21164 // JVNDB: JVNDB-2025-014168 // NVD: CVE-2025-57062

REFERENCES

url:https://github.com/vulndetailrecord/vulfordevice/blob/main/tenda/g3/formdeldhcprule.md

Trust: 1.8

url:https://nvd.nist.gov/vuln/detail/cve-2025-57062

Trust: 1.4

sources: CNVD: CNVD-2025-21164 // JVNDB: JVNDB-2025-014168 // NVD: CVE-2025-57062

SOURCES

db:CNVDid:CNVD-2025-21164
db:JVNDBid:JVNDB-2025-014168
db:NVDid:CVE-2025-57062

LAST UPDATE DATE

2025-09-23T23:32:58.213000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2025-21164date:2025-09-12T00:00:00
db:JVNDBid:JVNDB-2025-014168date:2025-09-22T06:57:00
db:NVDid:CVE-2025-57062date:2025-09-18T18:53:38.910

SOURCES RELEASE DATE

db:CNVDid:CNVD-2025-21164date:2025-09-12T00:00:00
db:JVNDBid:JVNDB-2025-014168date:2025-09-22T00:00:00
db:NVDid:CVE-2025-57062date:2025-09-09T17:16:08.827