Back

HIGH

Tenda M3 setVlanPolicyData formSetVlanPolicy heap-based overflow

Published Dec 30, 2025

Description

A vulnerability was found in Tenda M3 1.0.0.13(4903). Affected by this issue is the function formSetVlanPolicy of the file /goform/setVlanPolicyData. Performing a manipulation of the argument qvlan_truck_port results in heap-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made public and could be used.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Dec 30, 2025
Updated Feb 24, 2026
Reserved Dec 29, 2025
CISA Vulnrichment
Updated Dec 30, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a