VYPR
High severity8.8NVD Advisory· Published Dec 30, 2025· Updated Jun 17, 2026

CVE-2025-15217

CVE-2025-15217

Description

A security flaw has been discovered in Tenda AC23 16.03.07.52. Affected is the function formSetPPTPUserList of the component HTTP POST Request Handler. Performing a manipulation of the argument list results in buffer overflow. The attack can be initiated remotely.

Affected products

3
  • Tenda/AC23llm-fuzzy2 versions
    16.03.07.52+ 1 more
    • (no CPE)range: 16.03.07.52
    • cpe:2.3:o:tenda:ac23_firmware:*:*:*:*:*:*:*:*range: 16.03.07.52
  • cpe:2.3:o:tenda:ac23_firmware:16.03.07.52:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.