CVE-2025-44899: Tenda RX3 Firmware

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

There is a stack overflow vulnerability in Tenda RX3 V1.0br_V16.03.13.11 In the fromSetWifiGusetBasic function of the web url /goform/ WifiGuestSet, the manipulation of the parameter shareSpeed leads to stack overflow.

Affected products

  • Tenda RX3 Firmware: version 16.03.13.11_multi only

Published 2025-05-06. Last modified 2026-06-17.