CVE-2025-29359 Details
Description
Tenda RX3 US_RX3V1.0br_V16.03.13.11_multi_TDE01 is vulnerable to Buffer Overflow via the deviceId parameter at /goform/saveParentControlInfo. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.
A buffer overflow vulnerability has been identified in the Tenda RX3 router, specifically in the US_RX3V1.0br_V16.03.13.11_multi_TDE01 version. The issue arises in the '/goform/saveParentControlInfo' endpoint, where the 'deviceId' parameter is improperly handled. This vulnerability allows attackers to craft packets that trigger the buffer overflow, leading to a denial-of-service condition on the device.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 19, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/2664521593/mycve/blob/main/Tenda/RX3/tenda_rx3_bof_6.pdf | CISA-ADP | Exploit |
| https://github.com/2664521593/mycve/blob/main/Tenda/RX3/tenda_rx3_bof_6.pdf | [email protected] | Exploit |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-120 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| tenda rx3 firmware | 16.03.13.11_multi_tde01 |
CPE
Remediation
| |
| tenda rx3 | 1.0br |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 1, 2025 | Reanalysis | [email protected] |
| Apr 2, 2025 | Initial Analysis | [email protected] |
| Mar 19, 2025 | CVE Modified | CISA-ADP |
| Mar 13, 2025 | New CVE Received | [email protected] |