VYPR

Ac23 Firmware

by Tenda

CVEs (26)

  • CVE-2025-9605CriAug 29, 2025
    risk 0.64cvss 9.8epss 0.05

    A security vulnerability has been detected in Tenda AC21 and AC23 16.03.08.16. Affected is the function GetParentControlInfo of the file /goform/GetParentControlInfo. Such manipulation of the argument mac leads to stack-based buffer overflow. The attack can be launched remotely.…

  • CVE-2023-40799CriAug 25, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC23 Vv16.03.07.45_cn is vulnerable to Buffer Overflow via sub_450A4C function.

  • CVE-2022-43108CriNov 3, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the firewallEn parameter in the formSetFirewallCfg function.

  • CVE-2022-43107CriNov 3, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the time parameter in the setSmartPowerManagement function.

  • CVE-2022-43106CriNov 3, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the schedStartTime parameter in the setSchedWifi function.

  • CVE-2022-43105CriNov 3, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the shareSpeed parameter in the fromSetWifiGusetBasic function.

  • CVE-2022-43104CriNov 3, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the wpapsk_crypto parameter in the fromSetWirelessRepeat function.

  • CVE-2022-43103CriNov 3, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the list parameter in the formSetQosBand function.

  • CVE-2022-43102CriNov 3, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the timeZone parameter in the fromSetSysTime function.

  • CVE-2022-43101CriNov 3, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the devName parameter in the formSetDeviceName function.

  • CVE-2026-1420HigJan 26, 2026
    risk 0.57cvss 8.8epss 0.04

    A flaw has been found in Tenda AC23 16.03.07.52. This impacts an unknown function of the file /goform/WifiExtraSet. This manipulation of the argument wpapsk_crypto causes buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and may be…

  • CVE-2026-0640HigJan 6, 2026
    risk 0.57cvss 8.8epss 0.03

    A weakness has been identified in Tenda AC23 16.03.07.52. This affects the function sscanf of the file /goform/PowerSaveSet. Executing a manipulation of the argument Time can lead to buffer overflow. The attack can be launched remotely. The exploit has been made available to the…

  • CVE-2025-15217HigDec 30, 2025
    risk 0.57cvss 8.8epss 0.01

    A security flaw has been discovered in Tenda AC23 16.03.07.52. Affected is the function formSetPPTPUserList of the component HTTP POST Request Handler. Performing a manipulation of the argument list results in buffer overflow. The attack can be initiated remotely.

  • CVE-2025-15216HigDec 30, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was identified in Tenda AC23 16.03.07.52. This impacts the function fromSetIpMacBind of the file /goform/SetIpMacBind. Such manipulation of the argument bindnum leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit is…

  • CVE-2025-12596HigNov 2, 2025
    risk 0.57cvss 8.8epss 0.01

    A security vulnerability has been detected in Tenda AC23 16.03.07.52. Affected is the function saveParentControlInfo of the file /goform/saveParentControlInfo. Such manipulation of the argument Time leads to buffer overflow. It is possible to launch the attack remotely. The…

  • CVE-2025-12595HigNov 2, 2025
    risk 0.57cvss 8.8epss 0.01

    A weakness has been identified in Tenda AC23 16.03.07.52. This impacts the function formSetVirtualSer of the file /goform/SetVirtualServerCfg. This manipulation of the argument list causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been made…

  • CVE-2025-11356HigOct 7, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in Tenda AC23 up to 16.03.07.52. Affected by this issue is the function sscanf of the file /goform/SetStaticRouteCfg. The manipulation of the argument list results in buffer overflow. It is possible to launch the attack remotely. The exploit has been…

  • CVE-2025-10803HigSep 22, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been found in Tenda AC23 up to 16.03.07.52. Affected by this vulnerability is the function sscanf of the file /goform/SetPptpServerCfg of the component HTTP POST Request Handler. Such manipulation of the argument startIp leads to buffer overflow. It is…

  • CVE-2025-8060HigJul 23, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been found in Tenda AC23 16.03.07.52 and classified as critical. Affected by this vulnerability is the function sub_46C940 of the file /goform/setMacFilterCfg of the component httpd. The manipulation of the argument deviceList leads to stack-based buffer…

  • CVE-2023-40798HigAug 25, 2023
    risk 0.57cvss 8.8epss 0.01

    In Tenda AC23 v16.03.07.45_cn, the formSetIPv6status and formGetWanParameter functions do not authenticate user input parameters, resulting in a post-authentication stack overflow vulnerability.

Page 1 of 2