Junglewise Threat Intelligence

CVE-2025-57570: Tenda F3 buffer overflow in goform/setQoS QosList parameter

CVE-2025-57570 · Severity: medium · CVSS 5.6 · Published 2025-09-10

Technologies: Tenda F3, Tenda F3 Firmware. Vendors: Tenda.

Executive brief

The Tenda F3 router, a device used to provide wireless internet connectivity in homes and small offices, contains a security flaw in its Quality of Service (QoS) settings. An attacker could exploit this vulnerability to cause the device to crash or potentially execute unauthorized commands by sending specially crafted data. This could lead to a loss of internet connectivity or unauthorized access to the router's management functions.

Technical details

A classic buffer overflow (CWE-120) exists in the Tenda F3 router firmware versions 12.01.01.48_multi and subsequent releases. The vulnerability is located within the 'goform/setQoS' endpoint, specifically triggered by insufficient length validation of the 'QosList' parameter. An unauthenticated attacker can exploit this by sending a crafted HTTP request to the web management interface. While the CVSS assessment suggests high complexity (AC:H), successful exploitation could lead to memory corruption, resulting in a denial-of-service (DoS) condition or potential remote code execution. As of the advisory date, the status of a vendor-supplied patch is unclear, though the vulnerability has been publicly documented with proof-of-concept information.

Affected products

  • Tenda F3 Firmware 12.01.01.48_multi and later

Timeline

  • 2025-09-10: advisory: Initial NVD publication date
  • 2025-09-10: disclosed: Vulnerability details and PoC shared publicly

References

Related threats