Severity
7.4HIGH
EPSS
0.3%
top 50.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 22

Description

A vulnerability has been found in Tenda AC23 up to 16.03.07.52. Affected by this vulnerability is the function sscanf of the file /goform/SetPptpServerCfg of the component HTTP POST Request Handler. Such manipulation of the argument startIp leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Packages2 packages

NVDtenda/ac23_firmware16.03.07.52
CVEListV5tenda/ac2353 versions+52

🔴Vulnerability Details

2
GHSA
GHSA-jxff-p3fh-x5c9: A vulnerability has been found in Tenda AC23 up to 162025-09-22
CVEList
Tenda AC23 HTTP POST Request SetPptpServerCfg sscanf buffer overflow2025-09-22

🔍Detection Rules

1
Suricata
ET WEB_SPECIFIC_APPS Tenda AC7 SetPptpServerCfg Buffer Overflow Attempt (CVE-2025-3346, CVE-2025-10803, CVE-2025-10815)2025-04-07