ID

VAR-202601-1882


CVE

CVE-2025-71025


TITLE

Shenzhen Tenda Technology Co.,Ltd. of AX3  Multiple vulnerabilities in firmware

Trust: 0.8

sources: JVNDB: JVNDB-2026-001563

DESCRIPTION

Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the cloneType2 parameter of the fromAdvSetMacMtuWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. DoS ) may cause attacks.Information handled by the software will not be leaked to the outside. Information handled by the software will not be rewritten. In addition, the software may stop functioning completely. Furthermore, attacks that exploit this vulnerability will not affect other software

Trust: 1.62

sources: NVD: CVE-2025-71025 // JVNDB: JVNDB-2026-001563

AFFECTED PRODUCTS

vendor:tendamodel:ax3scope:eqversion:16.03.12.10_cn

Trust: 1.0

vendor:tendamodel:ax3scope:eqversion: -

Trust: 0.8

vendor:tendamodel:ax3scope:eqversion:ax3 firmware 16.03.12.10_cn

Trust: 0.8

vendor:tendamodel:ax3scope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2026-001563 // NVD: CVE-2025-71025

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2025-71025
value: HIGH

Trust: 1.0

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2025-71025
value: HIGH

Trust: 1.0

NVD: CVE-2025-71025
value: HIGH

Trust: 0.8

nvd@nist.gov: CVE-2025-71025
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.1

Trust: 2.0

NVD: CVE-2025-71025
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2026-001563 // NVD: CVE-2025-71025 // NVD: CVE-2025-71025

PROBLEMTYPE DATA

problemtype:CWE-121

Trust: 1.0

problemtype:CWE-787

Trust: 1.0

problemtype:Stack-based buffer overflow (CWE-121) [ others ]

Trust: 0.8

problemtype: Out-of-bounds writing (CWE-787) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2026-001563 // NVD: CVE-2025-71025

PATCH

title:VulnbyCola/Tenda/AX-3/10/1.md at main  0-fool/VulnbyCola  GitHuburl:https://github.com/0-fool/VulnbyCola/blob/main/Tenda/AX-3/10/1.md

Trust: 0.8

sources: JVNDB: JVNDB-2026-001563

EXTERNAL IDS

db:NVDid:CVE-2025-71025

Trust: 2.6

db:JVNDBid:JVNDB-2026-001563

Trust: 0.8

sources: JVNDB: JVNDB-2026-001563 // NVD: CVE-2025-71025

REFERENCES

url:https://github.com/0-fool/vulnbycola/blob/main/tenda/ax-3/10/1.md

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2025-71025

Trust: 0.8

sources: JVNDB: JVNDB-2026-001563 // NVD: CVE-2025-71025

SOURCES

db:JVNDBid:JVNDB-2026-001563
db:NVDid:CVE-2025-71025

LAST UPDATE DATE

2026-01-21T23:57:57.587000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2026-001563date:2026-01-19T10:40:00
db:NVDid:CVE-2025-71025date:2026-01-16T18:24:25.410

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2026-001563date:2026-01-19T00:00:00
db:NVDid:CVE-2025-71025date:2026-01-13T16:16:05.413