VYPR

AC23

by Tenda

CVEs (32)

  • CVE-2025-10803HigSep 22, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been found in Tenda AC23 up to 16.03.07.52. Affected by this vulnerability is the function sscanf of the file /goform/SetPptpServerCfg of the component HTTP POST Request Handler. Such manipulation of the argument startIp leads to buffer overflow. It is…

  • CVE-2025-8060HigJul 23, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been found in Tenda AC23 16.03.07.52 and classified as critical. Affected by this vulnerability is the function sub_46C940 of the file /goform/setMacFilterCfg of the component httpd. The manipulation of the argument deviceList leads to stack-based buffer…

  • CVE-2023-40798HigAug 25, 2023
    risk 0.57cvss 8.8epss 0.01

    In Tenda AC23 v16.03.07.45_cn, the formSetIPv6status and formGetWanParameter functions do not authenticate user input parameters, resulting in a post-authentication stack overflow vulnerability.

  • CVE-2023-40797HigAug 25, 2023
    risk 0.57cvss 8.8epss 0.01

    In Tenda AC23 v16.03.07.45_cn, the sub_4781A4 function does not validate the parameters entered by the user, resulting in a post-authentication stack overflow vulnerability.

  • CVE-2023-40801HigAug 25, 2023
    risk 0.57cvss 8.8epss 0.01

    The sub_451784 function does not validate the parameters entered by the user, resulting in a stack overflow vulnerability in Tenda AC23 v16.03.07.45_cn

  • CVE-2023-40800HigAug 25, 2023
    risk 0.57cvss 8.8epss 0.01

    The compare_parentcontrol_time function does not authenticate user input parameters, resulting in a post-authentication stack overflow vulnerability in Tenda AC23 v16.03.07.45_cn.

  • CVE-2022-32384HigJul 1, 2022
    risk 0.57cvss 8.8epss 0.01

    Tenda AC23 v16.03.07.44 was discovered to contain a stack overflow via the security_5g parameter in the function formWifiBasicSet.

  • CVE-2023-24334HigFeb 21, 2024
    risk 0.52cvss 8.0epss 0.00

    A stack overflow vulnerability in Tenda AC23 with firmware version US_AC23V1.0re_V16.03.07.45_cn_TDC01 allows attackers to run arbitrary commands via schedStartTime parameter.

  • CVE-2023-2649HigMay 11, 2023
    risk 0.48cvss 7.2epss 0.10

    A vulnerability was found in Tenda AC23 16.03.07.45_cn. It has been declared as critical. This vulnerability affects unknown code of the file /bin/ate of the component Service Port 7329. The manipulation of the argument v2 leads to command injection. The attack can be initiated…

  • CVE-2023-0782HigFeb 11, 2023
    risk 0.47cvss 7.2epss 0.01

    A vulnerability was found in Tenda AC23 16.03.07.45 and classified as critical. Affected by this issue is the function formSetSysToolDDNS/formGetSysToolDDNS of the file /bin/httpd. The manipulation leads to out-of-bounds write. The attack may be launched remotely. The exploit…

  • CVE-2025-3167MedApr 3, 2025
    risk 0.42cvss 6.5epss 0.01

    A vulnerability, which was classified as problematic, has been found in Tenda AC23 16.03.07.52. This issue affects some unknown processing of the file /goform/VerAPIMant of the component API Interface. The manipulation of the argument getuid leads to denial of service. The…

  • CVE-2023-40802MedAug 25, 2023
    risk 0.42cvss 6.5epss 0.01

    The get_parentControl_list_Info function does not verify the parameters entered by the user, causing a post-authentication heap overflow vulnerability in Tenda AC23 v16.03.07.45_cn

Page 2 of 2