Junglewise Threat Intelligence

CVE-2025-63152: Tenda AX3 V16.03.12.10_CN was discovered to contain a stack overflow in the wpapsk_crypto parameter of the wlSetExternParameter function. Th

CVE-2025-63152 · Severity: high · CVSS 7.5 · Published 2025-11-10

Vendors: Tenda.

Executive brief

Tenda AX3 V16.03.12.10_CN was discovered to contain a stack overflow in the wpapsk_crypto parameter of the wlSetExternParameter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

Affected products

  • tenda ax3_firmware
  • tenda ax3