CVE-2025-29358
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Mar 13, 2025
Updated: Apr 2, 2025
CWE ID 120
Summary
CVE-2025-29358 is a Buffer Overflow vulnerability affecting the Tenda RX3 US_RX3V1.0br_V16.03.13.11_multi_TDE01 firmware. Attackers can exploit this vulnerability by sending a crafted packet to the firewallEn parameter in the /goform/SetFirewallCfg endpoint. By overwriting the buffer, they can trigger a Denial of Service condition, making the device unresponsive to legitimate traffic. This vulnerability poses a serious threat to network availability and integrity, and users are advised to update their firmware to the latest version as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.