

Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the mac2 parameter of the fromAdvSetMacMtuWan function. This vulnerability allows attac…
Published:
12 January 2026 at 23:00:00
Alert date:
13 January 2026 at 20:04:16
Source:
nvd.nist.gov
Network Infrastructure, Mobile & IoT
CVE-2025-71023 affects Tenda AX-3 router firmware version 16.03.12.10_CN with a stack overflow vulnerability in the fromAdvSetMacMtuWan function. The vulnerability is located in the mac2 parameter and allows attackers to cause a Denial of Service (DoS) through crafted requests. This is a buffer overflow vulnerability that could potentially be exploited remotely. The vulnerability affects network infrastructure equipment, making it particularly concerning for network security. The issue has been documented with proof-of-concept details available on GitHub.
Technical details
Mitigation steps:
Affected products:
Tenda AX-3
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2025-71023
https://github.com/0-fool/VulnbyCola/blob/main/Tenda/AX-3/11/1.md
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.

