VYPR
Unrated severityNVD Advisory· Published Oct 7, 2025· Updated Feb 24, 2026

Tenda AC23 SetStaticRouteCfg sscanf buffer overflow

CVE-2025-11356

Description

A vulnerability was found in Tenda AC23 up to 16.03.07.52. Affected by this issue is the function sscanf of the file /goform/SetStaticRouteCfg. The manipulation of the argument list results in buffer overflow. It is possible to launch the attack remotely. The exploit has been made public and could be used.

Affected products

2
  • Tenda/AC23v5
    cpe:2.3:o:tenda:ac23_firmware:*:*:*:*:*:*:*:*
    Range: 16.03.07.0
  • Tenda/AC23llm-fuzzy
    Range: <=16.03.07.52

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.