cbcvebase.

Tenda Ac23 Firmware vulnerabilities

27 known vulnerabilities affecting tenda/ac23_firmware.

Total CVEs
27
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL15HIGH11MEDIUM1

Vulnerabilities

Page 2 of 2
CVE-2023-40800P3HIGHCVSS 8.8v16.03.07.45_cn2023-08-25
CVE-2023-40800 [HIGH] CWE-20 CVE-2023-40800: The compare_parentcontrol_time function does not authenticate user input parameters, resulting in a The compare_parentcontrol_time function does not authenticate user input parameters, resulting in a post-authentication stack overflow vulnerability in Tenda AC23 v16.03.07.45_cn.
nvd
CVE-2023-40798P3HIGHCVSS 8.8v16.03.07.45_cn2023-08-25
CVE-2023-40798 [HIGH] CWE-20 CVE-2023-40798: In Tenda AC23 v16.03.07.45_cn, the formSetIPv6status and formGetWanParameter functions do not authen In Tenda AC23 v16.03.07.45_cn, the formSetIPv6status and formGetWanParameter functions do not authenticate user input parameters, resulting in a post-authentication stack overflow vulnerability.
nvd
CVE-2023-40797P3HIGHCVSS 8.8v16.03.07.45_cn2023-08-25
CVE-2023-40797 [HIGH] CWE-20 CVE-2023-40797: In Tenda AC23 v16.03.07.45_cn, the sub_4781A4 function does not validate the parameters entered by t In Tenda AC23 v16.03.07.45_cn, the sub_4781A4 function does not validate the parameters entered by the user, resulting in a post-authentication stack overflow vulnerability.
nvd
CVE-2023-40799P3CRITICALCVSS 9.8v16.03.07.45_cn2023-08-25
CVE-2023-40799 [CRITICAL] CWE-787 CVE-2023-40799: Tenda AC23 Vv16.03.07.45_cn is vulnerable to Buffer Overflow via sub_450A4C function. Tenda AC23 Vv16.03.07.45_cn is vulnerable to Buffer Overflow via sub_450A4C function.
nvd
CVE-2023-24334P3HIGHCVSS 8.0v16.03.07.45_cn2024-02-21
CVE-2023-24334 [HIGH] CWE-121 CVE-2023-24334: A stack overflow vulnerability in Tenda AC23 with firmware version US_AC23V1.0re_V16.03.07.45_cn_TDC A stack overflow vulnerability in Tenda AC23 with firmware version US_AC23V1.0re_V16.03.07.45_cn_TDC01 allows attackers to run arbitrary commands via schedStartTime parameter.
nvd
CVE-2025-3167P3HIGHCVSS 7.5v16.03.07.522025-04-03
CVE-2025-3167 [HIGH] CWE-404 CVE-2025-3167: A vulnerability, which was classified as problematic, has been found in Tenda AC23 16.03.07.52. This A vulnerability, which was classified as problematic, has been found in Tenda AC23 16.03.07.52. This issue affects some unknown processing of the file /goform/VerAPIMant of the component API Interface. The manipulation of the argument getuid leads to denial of service. The attack may be initiated remotely. The exploit has been disclosed to the public an
nvd
CVE-2023-40802P3MEDIUMCVSS 6.5v16.03.07.45_cn2023-08-25
CVE-2023-40802 [MEDIUM] CWE-787 CVE-2023-40802: The get_parentControl_list_Info function does not verify the parameters entered by the user, causing The get_parentControl_list_Info function does not verify the parameters entered by the user, causing a post-authentication heap overflow vulnerability in Tenda AC23 v16.03.07.45_cn
nvd
Tenda Ac23 Firmware vulnerabilities | cvebase