CVE-2025-15216Improper Restriction of Operations within the Bounds of a Memory Buffer in Ac23

Severity
7.4HIGHNVD
EPSS
0.1%
top 71.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 30

Description

A vulnerability was identified in Tenda AC23 16.03.07.52. This impacts the function fromSetIpMacBind of the file /goform/SetIpMacBind. Such manipulation of the argument bindnum leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Packages2 packages

CVEListV5tenda/ac2316.03.07.52
NVDtenda/ac23_firmware16.03.07.52

🔴Vulnerability Details

2
GHSA
GHSA-vwcf-px28-cqjr: A vulnerability was identified in Tenda AC23 162025-12-30
CVEList
Tenda AC23 SetIpMacBind fromSetIpMacBind stack-based overflow2025-12-30

🔍Detection Rules

1
Suricata
ET WEB_SPECIFIC_APPS Tenda SetIpMacBind Multiple Parameters Buffer Overflow Attempt (CVE-2025-15216, CVE-2025-9089, CVE-2025-1853, CVE-2024-40417, CVE-2023-41556, CVE-2023-40902, CVE-2023-40896)2025-10-10
CVE-2025-15216 — Tenda Ac23 vulnerability | cvebase