CVE-2025-63455
7.5Tenda · AX-3
A stack overflow vulnerability in the Tenda AX-3 router allows unauthenticated remote attackers to trigger a denial of service condition via the shareSpeed parameter.
Executive summary
A critical stack overflow vulnerability in Tenda AX-3 firmware permits unauthenticated attackers to crash the device, leading to a complete denial of service.
Vulnerability
The device is susceptible to a stack overflow within the fromSetWifiGusetBasic function, triggered by sending a crafted shareSpeed parameter in an unauthenticated network request.
Business impact
This vulnerability poses a significant risk to network availability, as it allows any remote, unauthenticated attacker to render the router non-functional. With a CVSS score of 7.5, the flaw represents a high risk to business continuity, potentially disrupting all services and operations dependent on the affected network infrastructure.
Remediation
Immediate Action: Since a vendor-provided patch is currently unknown, administrators should restrict management interface access to trusted IP addresses or internal networks only.
Proactive Monitoring: Review system logs for frequent reboots or crash patterns, and monitor network traffic for anomalous requests directed at the wireless configuration endpoints.
Compensating Controls: Deploy a Web Application Firewall or an intrusion prevention system to filter and block malformed packets containing excessively large shareSpeed parameters.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept exists as detailed in the technical write-up referenced by the CVE record.
Analyst recommendation
The Tenda AX-3 router is exposed to a critical denial of service risk due to poor input validation in the firmware. Given the availability of a public proof-of-concept, organizations should prioritize isolating these devices from the public internet immediately. Monitor vendor communications closely for the release of a firmware update and apply it as soon as it becomes available.