Sploit.io - Search

Product: W12, version: 3.0.0.4(2887)

CVE-2025-3802

Severity: Unknown

Description: A vulnerability was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644). It has been declared as critical. This vulnerability affects the function cgiPingSet of the file /bin/httpd. The manipulation of the argument pingIP leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS Score: N/A

Affected Products:

  • Tenda W12 - Versions: 3.0.0.4(2887), 3.0.0.5(3644)
  • Tenda i24 - Versions: 3.0.0.4(2887), 3.0.0.5(3644)

References:

CVE-2025-3803

Severity: Unknown

Description: A vulnerability was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644). It has been rated as critical. This issue affects the function cgiSysScheduleRebootSet of the file /bin/httpd. The manipulation of the argument rebootDate leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVSS Score: N/A

Affected Products:

  • Tenda W12 - Versions: 3.0.0.4(2887), 3.0.0.5(3644)
  • Tenda i24 - Versions: 3.0.0.4(2887), 3.0.0.5(3644)

References:

CVE-2025-3820

Severity: Unknown

Description: A vulnerability was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644) and classified as critical. Affected by this issue is the function cgiSysUplinkCheckSet of the file /bin/httpd. The manipulation of the argument hostIp1/hostIp2 leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS Score: N/A

Affected Products:

  • Tenda W12 - Versions: 3.0.0.4(2887), 3.0.0.5(3644)
  • Tenda i24 - Versions: 3.0.0.4(2887), 3.0.0.5(3644)

References: