Stack Buffer Overflow Vulnerabilities in D-Link and Tenda Devices

Stack Buffer Overflow Vulnerabilities in D-Link and Tenda Devices

First seen 4 Mar 2026, 18:11 UTC Nvd.Nist 69.0

Article Content

Browse articles
ThreatCluster

Two critical stack buffer overflow vulnerabilities have been identified in D-Link DIR-513 and Tenda AX3 devices, both allowing potential remote code execution. CVE-2025-70237 affects D-Link's firmware via the curTime parameter, while CVE-2025-69765 impacts Tenda's firmware through the formGetIptv function. Both vulnerabilities were published on March 3, 2026.

Timeline

2026-03-03
CVE-2025-70237 published
2026-03-03
CVE-2025-69765 published
2026-03-04
Articles published detailing vulnerabilities