CVE-2025-29359
Published: 13 March 2025
Description
Adversaries may exploit software vulnerabilities that can cause an application or system to crash and deny availability to users.
Security Summary
CVE-2025-29359 is a buffer overflow vulnerability (CWE-120) in the Tenda RX3 router firmware version US_RX3V1.0br_V16.03.13.11_multi_TDE01. The flaw resides in the handling of the deviceId parameter within the /goform/saveParentControlInfo endpoint, which can be triggered by specially crafted input.
The vulnerability carries a CVSS v3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H), indicating it is exploitable over the network with low complexity, no authentication or user interaction required. Remote attackers can send a crafted packet to the affected endpoint, causing a denial of service by crashing the device and disrupting network availability.
Further technical details, including proof-of-concept information, are documented in the referenced analysis at https://github.com/2664521593/mycve/blob/main/Tenda/RX3/tenda_rx3_bof_6.pdf. No official vendor patches or mitigation guidance are specified in available sources.
Details
- CWE(s)
Affected Products
MITRE ATT&CK Enterprise Techniques
Why these techniques?
Buffer overflow in public-facing web endpoint (/goform/saveParentControlInfo) enables remote exploitation (T1190) leading to device crash/DoS via application exploitation (T1499.004).