Junglewise Threat Intelligence

CVE-2025-57572: Tenda F3 buffer overflow in goform/setParentControl

CVE-2025-57572 · Severity: medium · CVSS 5.6 · Published 2025-09-10

Technologies: Tenda F3, Tenda F3 Firmware. Vendors: Tenda.

Executive brief

The Tenda F3 is a wireless router used for home and small office networking. A security flaw in its parental control settings allows an attacker to send specially crafted data that can crash the device or potentially allow unauthorized code execution. This could lead to a loss of internet connectivity or a compromise of the router's security.

Technical details

A classic buffer overflow (CWE-120) exists in the Tenda F3 router firmware versions V12.01.01.48_multi and subsequent releases. The vulnerability is located within the 'goform/setParentControl' endpoint and is triggered by providing an overly long string to the 'onlineList' parameter. An unauthenticated attacker can exploit this over a network, though the attack complexity is rated as high, likely due to specific environmental or configuration requirements. Successful exploitation can lead to a denial-of-service (DoS) condition or potentially remote code execution (RCE).

Affected products

  • Tenda F3 V12.01.01.48_multi and later

Timeline

  • 2025-09-10: disclosed
  • 2025-09-10: advisory

References

Related threats