LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2025-69765

CVE-2025-69765 - Vulnerability Analysis

HighCVSS: 7.5

Last Updated: March 4, 2026

Tenda AX3 - Remote Code Execution

Published: March 3, 2026Updated: March 4, 2026PoC AvailableRemote Exploitable

Overview

Tenda AX3 firmware v16.03.12.11 contains a stack overflow caused by improper handling of the list parameter in formGetIptv function, letting remote attackers execute arbitrary code, exploit requires crafted request.

Severity & Score

Severity: High
CVSS Score: 7.5
EPSS Score: 24.6%(Probability of exploitation in next 30 days)

Impact

Remote attackers can execute arbitrary code, potentially taking full control of the device.

Mitigation

Update to the latest firmware version.

Social Media Activity(1 post)

TheHackerWire
TheHackerWire
@thehackerwire
Mar 4, 2026

🟠 CVE-2025-69765 - High (7.5) Tenda AX3 firmware v16.03.12.11 contains a stack overflow in formGetIptv function and the list parameter, which can cause memory corruption and enable remote code execution. šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2025-69765/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2025-69765
Severity
High
CVSS Score
7.5
Type
buffer_overflow
Status
confirmed
EPSS
24.6%
Social Posts
1

CWE

  • CWE-121

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Score

24.6%Probability of exploitation in the next 30 days