VendorsTendaac23all versions
Vulnerabilities

Tenda AC23

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

28CVEs
CVE-2025-9605
Tenda AC21/AC23 GetParentControlInfo stack-based overflow
Published 2025-08-29 · Analyzed
10.0EPSS 0.051
CVE-2026-1420
Tenda AC23 WifiExtraSet buffer overflow
Published 2026-01-26 · Analyzed
9.8EPSS 0.039
CVE-2026-0640
Tenda AC23 PowerSaveSet sscanf buffer overflow
Published 2026-01-06 · Analyzed
9.8EPSS 0.034
CVE-2023-0782
Tenda AC23 httpd formGetSysToolDDNS out-of-bounds write
Published 2023-02-11 · Modified
9.8EPSS 0.015
CVE-2025-12596
Tenda AC23 saveParentControlInfo buffer overflow
Published 2025-11-02 · Analyzed
9.8EPSS 0.011
CVE-2025-12595
Tenda AC23 SetVirtualServerCfg formSetVirtualSer buffer overflow
Published 2025-11-02 · Modified
9.8EPSS 0.010
CVE-2022-43102
Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the timeZone parameter in the fromSetSysTime function.
Published 2022-11-03 · Modified
9.8EPSS 0.010
CVE-2022-43107
Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the time parameter in the setSmartPowerManagement function.
Published 2022-11-03 · Modified
9.8EPSS 0.010
CVE-2022-43101
Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the devName parameter in the formSetDeviceName function.
Published 2022-11-03 · Modified
9.8EPSS 0.010
CVE-2022-43103
Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the list parameter in the formSetQosBand function.
Published 2022-11-03 · Modified
9.8EPSS 0.010
CVE-2022-43104
Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the wpapsk_crypto parameter in the fromSetWirelessRepeat function.
Published 2022-11-03 · Modified
9.8EPSS 0.010
CVE-2022-43105
Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the shareSpeed parameter in the fromSetWifiGusetBasic function.
Published 2022-11-03 · Modified
9.8EPSS 0.010
CVE-2022-43106
Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the schedStartTime parameter in the setSchedWifi function.
Published 2022-11-03 · Modified
9.8EPSS 0.010
CVE-2022-43108
Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the firewallEn parameter in the formSetFirewallCfg function.
Published 2022-11-03 · Modified
9.8EPSS 0.010
CVE-2023-40799
Tenda AC23 Vv16.03.07.45_cn is vulnerable to Buffer Overflow via sub_450A4C function.
Published 2023-08-25 · Modified
9.8EPSS 0.009
CVE-2025-8060
Tenda AC23 httpd setMacFilterCfg sub_46C940 stack-based overflow
Published 2025-07-23 · Analyzed
9.0EPSS 0.008
CVE-2025-11356
Tenda AC23 SetStaticRouteCfg sscanf buffer overflow
Published 2025-10-07 · Analyzed
9.0EPSS 0.008
CVE-2025-10803
Tenda AC23 HTTP POST Request SetPptpServerCfg sscanf buffer overflow
Published 2025-09-22 · Analyzed
9.0EPSS 0.008
CVE-2025-15217
Tenda AC23 HTTP POST Request formSetPPTPUserList buffer overflow
Published 2025-12-30 · Modified
9.0EPSS 0.007
CVE-2025-15216
Tenda AC23 SetIpMacBind fromSetIpMacBind stack-based overflow
Published 2025-12-30 · Analyzed
9.0EPSS 0.007
CVE-2023-2649
Tenda AC23 Service Port 7329 ate command injection
Published 2023-05-11 · Modified
8.8EPSS 0.097
CVE-2023-40800
The compare_parentcontrol_time function does not authenticate user input parameters, resulting in a post-authentication stack overflow vulnerability in Tenda AC23 v16.03.07.45_cn.
Published 2023-08-25 · Modified
8.8EPSS 0.010
CVE-2023-40798
In Tenda AC23 v16.03.07.45_cn, the formSetIPv6status and formGetWanParameter functions do not authenticate user input parameters, resulting in a post-authentication stack overflow vulnerability.
Published 2023-08-25 · Modified
8.8EPSS 0.010
CVE-2023-40797
In Tenda AC23 v16.03.07.45_cn, the sub_4781A4 function does not validate the parameters entered by the user, resulting in a post-authentication stack overflow vulnerability.
Published 2023-08-25 · Modified
8.8EPSS 0.010
CVE-2023-40801
The sub_451784 function does not validate the parameters entered by the user, resulting in a stack overflow vulnerability in Tenda AC23 v16.03.07.45_cn
Published 2023-08-25 · Modified
8.8EPSS 0.009
CVE-2023-24334
A stack overflow vulnerability in Tenda AC23 with firmware version US_AC23V1.0re_V16.03.07.45_cn_TDC01 allows attackers to run arbitrary commands via schedStartTime parameter.
Published 2024-02-21 · Analyzed
8.0EPSS 0.005
CVE-2025-3167
Tenda AC23 API Interface VerAPIMant denial of service
Published 2025-04-03 · Analyzed
7.5EPSS 0.009
CVE-2023-40802
The get_parentControl_list_Info function does not verify the parameters entered by the user, causing a post-authentication heap overflow vulnerability in Tenda AC23 v16.03.07.45_cn
Published 2023-08-25 · Modified
6.5EPSS 0.008