VYPR

AC23

by Tenda

CVEs (32)

  • CVE-2022-32386CriJul 6, 2022
    risk 0.65cvss 9.8epss 0.11

    Tenda AC23 v16.03.07.44 was discovered to contain a buffer overflow via fromAdvSetMacMtuWan.

  • CVE-2023-40799CriAug 25, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC23 Vv16.03.07.45_cn is vulnerable to Buffer Overflow via sub_450A4C function.

  • CVE-2022-43108CriNov 3, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the firewallEn parameter in the formSetFirewallCfg function.

  • CVE-2022-43107CriNov 3, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the time parameter in the setSmartPowerManagement function.

  • CVE-2022-43106CriNov 3, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the schedStartTime parameter in the setSchedWifi function.

  • CVE-2022-43105CriNov 3, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the shareSpeed parameter in the fromSetWifiGusetBasic function.

  • CVE-2022-43104CriNov 3, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the wpapsk_crypto parameter in the fromSetWirelessRepeat function.

  • CVE-2022-43103CriNov 3, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the list parameter in the formSetQosBand function.

  • CVE-2022-43102CriNov 3, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the timeZone parameter in the fromSetSysTime function.

  • CVE-2022-43101CriNov 3, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the devName parameter in the formSetDeviceName function.

  • CVE-2022-32385CriJul 6, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC23 v16.03.07.44 is vulnerable to Stack Overflow that will allow for the execution of arbitrary code (remote).

  • CVE-2022-32383CriJul 6, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC23 v16.03.07.44 was discovered to contain a stack overflow via the AdvSetMacMtuWan function.

  • CVE-2025-8060HigJul 23, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been found in Tenda AC23 16.03.07.52 and classified as critical. Affected by this vulnerability is the function sub_46C940 of the file /goform/setMacFilterCfg of the component httpd. The manipulation of the argument deviceList leads to stack-based buffer…

  • CVE-2023-40798HigAug 25, 2023
    risk 0.57cvss 8.8epss 0.01

    In Tenda AC23 v16.03.07.45_cn, the formSetIPv6status and formGetWanParameter functions do not authenticate user input parameters, resulting in a post-authentication stack overflow vulnerability.

  • CVE-2023-40797HigAug 25, 2023
    risk 0.57cvss 8.8epss 0.01

    In Tenda AC23 v16.03.07.45_cn, the sub_4781A4 function does not validate the parameters entered by the user, resulting in a post-authentication stack overflow vulnerability.

  • CVE-2023-40801HigAug 25, 2023
    risk 0.57cvss 8.8epss 0.01

    The sub_451784 function does not validate the parameters entered by the user, resulting in a stack overflow vulnerability in Tenda AC23 v16.03.07.45_cn

  • CVE-2023-40800HigAug 25, 2023
    risk 0.57cvss 8.8epss 0.01

    The compare_parentcontrol_time function does not authenticate user input parameters, resulting in a post-authentication stack overflow vulnerability in Tenda AC23 v16.03.07.45_cn.

  • CVE-2022-32384HigJul 1, 2022
    risk 0.57cvss 8.8epss 0.01

    Tenda AC23 v16.03.07.44 was discovered to contain a stack overflow via the security_5g parameter in the function formWifiBasicSet.

  • CVE-2023-24334HigFeb 21, 2024
    risk 0.52cvss 8.0epss 0.00

    A stack overflow vulnerability in Tenda AC23 with firmware version US_AC23V1.0re_V16.03.07.45_cn_TDC01 allows attackers to run arbitrary commands via schedStartTime parameter.

  • CVE-2023-2649HigMay 11, 2023
    risk 0.48cvss 7.2epss 0.10

    A vulnerability was found in Tenda AC23 16.03.07.45_cn. It has been declared as critical. This vulnerability affects unknown code of the file /bin/ate of the component Service Port 7329. The manipulation of the argument v2 leads to command injection. The attack can be initiated…

Page 1 of 2