CVE-2025-29361
Published: 13 March 2025
Description
Adversaries may exploit software vulnerabilities that can cause an application or system to crash and deny availability to users.
Security Summary
CVE-2025-29361 is a buffer overflow vulnerability (CWE-120) affecting the Tenda RX3 router running firmware version US_RX3V1.0br_V16.03.13.11_multi_TDE01. The issue resides in the handling of the "list" parameter within the /goform/SetVirtualServerCfg endpoint, where insufficient bounds checking allows overflow conditions when processing malformed input.
The vulnerability carries a CVSS v3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H), indicating high severity due to its network accessibility without authentication or user interaction. Remote attackers can exploit it by sending a specially crafted packet to the vulnerable endpoint, triggering the buffer overflow and causing a denial-of-service condition that crashes the device.
References for this CVE include detailed documentation in PDF format hosted on GitHub at https://github.com/2664521593/mycve/blob/main/Tenda/RX3/tenda_rx3_bof_5.pdf, which likely provides proof-of-concept exploit details, though specific mitigation or patch guidance is not detailed in the available CVE information.
Details
- CWE(s)
Affected Products
MITRE ATT&CK Enterprise Techniques
Why these techniques?
Buffer overflow in public-facing router web endpoint (/goform/SetVirtualServerCfg) directly enables remote exploitation of the application (T1190) to crash the device and deny service (T1499.004).