Skip to main content

Vendor/product archive

tenda / ac23_firmware CVEs

Beta · best-effort

28 CVEs tagged to tenda / ac23_firmware9 Critical, 18 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2026-1420

Published Jan 26, 2026

A flaw has been found in Tenda AC23 16.03.07.52. This impacts an unknown function of the file /goform/WifiExtraSet. This manipulation of the argument wpapsk_crypto causes buffer o…

CVSS 7.4 · High
evidence mentions
6
Buzz score
31.0
Vendor/product tagsBeta · best-effort

CVE-2026-0640

Published Jan 6, 2026

A weakness has been identified in Tenda AC23 16.03.07.52. This affects the function sscanf of the file /goform/PowerSaveSet. Executing a manipulation of the argument Time can lead…

CVSS 7.4 · High
evidence mentions
6
Buzz score
31.0
Vendor/product tagsBeta · best-effort

CVE-2025-15217

Published Dec 30, 2025

A security flaw has been discovered in Tenda AC23 16.03.07.52. Affected is the function formSetPPTPUserList of the component HTTP POST Request Handler. Performing a manipulation o…

CVSS 7.4 · High
evidence mentions
6
Buzz score
31.0
Vendor/product tagsBeta · best-effort

CVE-2025-15216

Published Dec 30, 2025

A vulnerability was identified in Tenda AC23 16.03.07.52. This impacts the function fromSetIpMacBind of the file /goform/SetIpMacBind. Such manipulation of the argument bindnum le…

CVSS 7.4 · High
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2025-12596

Published Nov 2, 2025

A security vulnerability has been detected in Tenda AC23 16.03.07.52. Affected is the function saveParentControlInfo of the file /goform/saveParentControlInfo. Such manipulation o…

CVSS 7.4 · High
evidence mentions
6
Buzz score
40.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-12595

Published Nov 2, 2025

A weakness has been identified in Tenda AC23 16.03.07.52. This impacts the function formSetVirtualSer of the file /goform/SetVirtualServerCfg. This manipulation of the argument li…

CVSS 7.4 · High
evidence mentions
6
Buzz score
40.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-11356

Published Oct 7, 2025

A vulnerability was found in Tenda AC23 up to 16.03.07.52. Affected by this issue is the function sscanf of the file /goform/SetStaticRouteCfg. The manipulation of the argument li…

CVSS 7.4 · High
evidence mentions
5
Buzz score
33.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-10803

Published Sep 22, 2025

A vulnerability has been found in Tenda AC23 up to 16.03.07.52. Affected by this vulnerability is the function sscanf of the file /goform/SetPptpServerCfg of the component HTTP PO…

CVSS 7.4 · High
evidence mentions
5
Buzz score
33.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-8060

Published Jul 23, 2025

A vulnerability has been found in Tenda AC23 16.03.07.52 and classified as critical. Affected by this vulnerability is the function sub_46C940 of the file /goform/setMacFilterCfg…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2025-3167

Published Apr 3, 2025

A vulnerability, which was classified as problematic, has been found in Tenda AC23 16.03.07.52. This issue affects some unknown processing of the file /goform/VerAPIMant of the co…

CVSS 7.1 · High
evidence mentions
5
Buzz score
33.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2023-24334

Published Feb 21, 2024

A stack overflow vulnerability in Tenda AC23 with firmware version US_AC23V1.0re_V16.03.07.45_cn_TDC01 allows attackers to run arbitrary commands via schedStartTime parameter.

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2023-40798

Published Aug 25, 2023

In Tenda AC23 v16.03.07.45_cn, the formSetIPv6status and formGetWanParameter functions do not authenticate user input parameters, resulting in a post-authentication stack overflow…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-40797

Published Aug 25, 2023

In Tenda AC23 v16.03.07.45_cn, the sub_4781A4 function does not validate the parameters entered by the user, resulting in a post-authentication stack overflow vulnerability.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-40802

Published Aug 25, 2023

The get_parentControl_list_Info function does not verify the parameters entered by the user, causing a post-authentication heap overflow vulnerability in Tenda AC23 v16.03.07.45_cn

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-40801

Published Aug 25, 2023

The sub_451784 function does not validate the parameters entered by the user, resulting in a stack overflow vulnerability in Tenda AC23 v16.03.07.45_cn

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-40800

Published Aug 25, 2023

The compare_parentcontrol_time function does not authenticate user input parameters, resulting in a post-authentication stack overflow vulnerability in Tenda AC23 v16.03.07.45_cn.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-2649

Published May 11, 2023

A vulnerability was found in Tenda AC23 16.03.07.45_cn. It has been declared as critical. This vulnerability affects unknown code of the file /bin/ate of the component Service Por…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-0782

Published Feb 11, 2023

A vulnerability was found in Tenda AC23 16.03.07.45 and classified as critical. Affected by this issue is the function formSetSysToolDDNS/formGetSysToolDDNS of the file /bin/httpd…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-43105

Published Nov 3, 2022

Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the shareSpeed parameter in the fromSetWifiGusetBasic function.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-43104

Published Nov 3, 2022

Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the wpapsk_crypto parameter in the fromSetWirelessRepeat function.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-25 of 28 CVEsPage 1 of 2