CVE-2025-29358
Published: 13 March 2025
Description
Adversaries may exploit software vulnerabilities that can cause an application or system to crash and deny availability to users.
Security Summary
CVE-2025-29358 is a buffer overflow vulnerability (CWE-120) in the Tenda RX3 router firmware version US_RX3V1.0br_V16.03.13.11_multi_TDE01. The flaw occurs in the handling of the firewallEn parameter via the /goform/SetFirewallCfg endpoint, which can be triggered by a specially crafted packet.
Remote attackers can exploit this vulnerability without authentication or user interaction, as indicated by the CVSS v3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H (base score 7.5). Successful exploitation results in a Denial of Service (DoS) condition, potentially crashing the device and disrupting network connectivity.
Advisories reference a technical document at https://github.com/2664521593/mycve/blob/main/Tenda/RX3/tenda_rx3_bof_2.pdf (listed twice), which details the vulnerability. No specific patches or mitigation guidance are provided in the available description.
Details
- CWE(s)
Affected Products
MITRE ATT&CK Enterprise Techniques
Why these techniques?
Buffer overflow in unauthenticated public web endpoint (/goform/SetFirewallCfg) directly enables T1190 for remote exploitation of public-facing application; results in system crash/DoS via T1499.004 Application or System Exploitation.