Tenda Ac23 Firmware vulnerabilities
27 known vulnerabilities affecting tenda/ac23_firmware.
Total CVEs
27
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL15HIGH11MEDIUM1
Vulnerabilities
Page 1 of 2
CVE-2025-9605P2CRITICALCVSS 9.8v16.03.08.162025-08-29
CVE-2025-9605 [CRITICAL] CWE-119 CVE-2025-9605: A security vulnerability has been detected in Tenda AC21 and AC23 16.03.08.16. Affected is the funct
A security vulnerability has been detected in Tenda AC21 and AC23 16.03.08.16. Affected is the function GetParentControlInfo of the file /goform/GetParentControlInfo. Such manipulation of the argument mac leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
nvd
CVE-2026-1420P2CRITICALCVSS 9.8v16.03.07.522026-01-26
CVE-2026-1420 [CRITICAL] CWE-119 CVE-2026-1420: A flaw has been found in Tenda AC23 16.03.07.52. This impacts an unknown function of the file /gofor
A flaw has been found in Tenda AC23 16.03.07.52. This impacts an unknown function of the file /goform/WifiExtraSet. This manipulation of the argument wpapsk_crypto causes buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and may be used.
nvd
CVE-2026-0640P2CRITICALCVSS 9.8v16.03.07.522026-01-06
CVE-2026-0640 [CRITICAL] CWE-119 CVE-2026-0640: A weakness has been identified in Tenda AC23 16.03.07.52. This affects the function sscanf of the fi
A weakness has been identified in Tenda AC23 16.03.07.52. This affects the function sscanf of the file /goform/PowerSaveSet. Executing a manipulation of the argument Time can lead to buffer overflow. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.
nvd
CVE-2023-2649P2HIGHCVSS 8.8v16.03.07.45_cn2023-05-11
CVE-2023-2649 [HIGH] CWE-77 CVE-2023-2649: A vulnerability was found in Tenda AC23 16.03.07.45_cn. It has been declared as critical. This vulne
A vulnerability was found in Tenda AC23 16.03.07.45_cn. It has been declared as critical. This vulnerability affects unknown code of the file /bin/ate of the component Service Port 7329. The manipulation of the argument v2 leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-2
nvd
CVE-2025-8060P2HIGHCVSS 8.8v16.03.07.522025-07-23
CVE-2025-8060 [HIGH] CWE-119 CVE-2025-8060: A vulnerability has been found in Tenda AC23 16.03.07.52 and classified as critical. Affected by thi
A vulnerability has been found in Tenda AC23 16.03.07.52 and classified as critical. Affected by this vulnerability is the function sub_46C940 of the file /goform/setMacFilterCfg of the component httpd. The manipulation of the argument deviceList leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to
nvd
CVE-2025-15216P2HIGHCVSS 8.8v16.03.07.522025-12-30
CVE-2025-15216 [HIGH] CWE-119 CVE-2025-15216: A vulnerability was identified in Tenda AC23 16.03.07.52. This impacts the function fromSetIpMacBind
A vulnerability was identified in Tenda AC23 16.03.07.52. This impacts the function fromSetIpMacBind of the file /goform/SetIpMacBind. Such manipulation of the argument bindnum leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
nvd
CVE-2025-12596P2CRITICALCVSS 9.8v16.03.07.522025-11-02
CVE-2025-12596 [CRITICAL] CWE-119 CVE-2025-12596: A security vulnerability has been detected in Tenda AC23 16.03.07.52. Affected is the function saveP
A security vulnerability has been detected in Tenda AC23 16.03.07.52. Affected is the function saveParentControlInfo of the file /goform/saveParentControlInfo. Such manipulation of the argument Time leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
nvd
CVE-2025-10803P2HIGHCVSS 8.8≤ 16.03.07.522025-09-22
CVE-2025-10803 [HIGH] CWE-119 CVE-2025-10803: A vulnerability has been found in Tenda AC23 up to 16.03.07.52. Affected by this vulnerability is th
A vulnerability has been found in Tenda AC23 up to 16.03.07.52. Affected by this vulnerability is the function sscanf of the file /goform/SetPptpServerCfg of the component HTTP POST Request Handler. Such manipulation of the argument startIp leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the pu
nvd
CVE-2025-12595P2CRITICALCVSS 9.8v16.03.07.522025-11-02
CVE-2025-12595 [CRITICAL] CWE-119 CVE-2025-12595: A weakness has been identified in Tenda AC23 16.03.07.52. This impacts the function formSetVirtualSe
A weakness has been identified in Tenda AC23 16.03.07.52. This impacts the function formSetVirtualSer of the file /goform/SetVirtualServerCfg. This manipulation of the argument list causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.
nvd
CVE-2025-11356P2HIGHCVSS 8.8v16.03.07.522025-10-07
CVE-2025-11356 [HIGH] CWE-119 CVE-2025-11356: A vulnerability was found in Tenda AC23 up to 16.03.07.52. Affected by this issue is the function ss
A vulnerability was found in Tenda AC23 up to 16.03.07.52. Affected by this issue is the function sscanf of the file /goform/SetStaticRouteCfg. The manipulation of the argument list results in buffer overflow. It is possible to launch the attack remotely. The exploit has been made public and could be used.
nvd
CVE-2025-15217P2HIGHCVSS 8.8v16.03.07.522025-12-30
CVE-2025-15217 [HIGH] CWE-119 CVE-2025-15217: A security flaw has been discovered in Tenda AC23 16.03.07.52. Affected is the function formSetPPTPU
A security flaw has been discovered in Tenda AC23 16.03.07.52. Affected is the function formSetPPTPUserList of the component HTTP POST Request Handler. Performing a manipulation of the argument list results in buffer overflow. The attack can be initiated remotely.
nvd
CVE-2022-43105P3CRITICALCVSS 9.8v16.03.07.45_cn2022-11-03
CVE-2022-43105 [CRITICAL] CWE-787 CVE-2022-43105: Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the shareSpeed parameter i
Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the shareSpeed parameter in the fromSetWifiGusetBasic function.
nvd
CVE-2022-43104P3CRITICALCVSS 9.8v16.03.07.45_cn2022-11-03
CVE-2022-43104 [CRITICAL] CWE-787 CVE-2022-43104: Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the wpapsk_crypto paramete
Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the wpapsk_crypto parameter in the fromSetWirelessRepeat function.
nvd
CVE-2022-43101P3CRITICALCVSS 9.8v16.03.07.45_cn2022-11-03
CVE-2022-43101 [CRITICAL] CWE-787 CVE-2022-43101: Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the devName parameter in t
Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the devName parameter in the formSetDeviceName function.
nvd
CVE-2022-43108P3CRITICALCVSS 9.8v16.03.07.45_cn2022-11-03
CVE-2022-43108 [CRITICAL] CWE-787 CVE-2022-43108: Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the firewallEn parameter i
Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the firewallEn parameter in the formSetFirewallCfg function.
nvd
CVE-2022-43102P3CRITICALCVSS 9.8v16.03.07.45_cn2022-11-03
CVE-2022-43102 [CRITICAL] CWE-787 CVE-2022-43102: Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the timeZone parameter in
Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the timeZone parameter in the fromSetSysTime function.
nvd
CVE-2022-43107P3CRITICALCVSS 9.8v16.03.07.45_cn2022-11-03
CVE-2022-43107 [CRITICAL] CWE-787 CVE-2022-43107: Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the time parameter in the
Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the time parameter in the setSmartPowerManagement function.
nvd
CVE-2022-43106P3CRITICALCVSS 9.8v16.03.07.45_cn2022-11-03
CVE-2022-43106 [CRITICAL] CWE-787 CVE-2022-43106: Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the schedStartTime paramet
Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the schedStartTime parameter in the setSchedWifi function.
nvd
CVE-2022-43103P3CRITICALCVSS 9.8v16.03.07.45_cn2022-11-03
CVE-2022-43103 [CRITICAL] CWE-787 CVE-2022-43103: Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the list parameter in the
Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the list parameter in the formSetQosBand function.
nvd
CVE-2023-0782P3CRITICALCVSS 9.8v16.03.07.452023-02-11
CVE-2023-0782 [CRITICAL] CWE-787 CVE-2023-0782: A vulnerability was found in Tenda AC23 16.03.07.45 and classified as critical. Affected by this iss
A vulnerability was found in Tenda AC23 16.03.07.45 and classified as critical. Affected by this issue is the function formSetSysToolDDNS/formGetSysToolDDNS of the file /bin/httpd. The manipulation leads to out-of-bounds write. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this v
nvd
1 / 2Next →