VYPR
High severity8.8NVD Advisory· Published Aug 15, 2025· Updated Jun 17, 2026

CVE-2025-9023

CVE-2025-9023

Description

A vulnerability has been found in Tenda AC7 and AC18 15.03.05.19/15.03.06.44. Affected is the function formSetSchedLed of the file /goform/SetLEDCfg. The manipulation of the argument Time leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • cpe:2.3:o:tenda:ac18_firmware:15.03.05.19:*:*:*:*:*:*:*
  • cpe:2.3:o:tenda:ac7_firmware:15.03.06.44:*:*:*:*:*:*:*
  • Tenda/AC7llm-fuzzy2 versions
    15.03.05.19/15.03.06.44+ 1 more
    • (no CPE)range: 15.03.05.19/15.03.06.44
    • (no CPE)range: 15.03.05.19
  • Tenda/AC18llm-fuzzy2 versions
    15.03.05.19/15.03.06.44+ 1 more
    • (no CPE)range: 15.03.05.19/15.03.06.44
    • (no CPE)range: 15.03.05.19

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.