Tenda
Tenda Ac23 Firmware: vulnerabilidades y CVE
Tenda Ac23 Firmware tiene 27 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 10 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE27
Últimos 12 meses7
Críticas10
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-1420 | Alta (7.4) | 3.9% | — | 26 ene 2026 | A flaw has been found in Tenda AC23 16.03.07.52. This impacts an unknown function of the file /goform/WifiExtraSet. This manipulation of the argument wpapsk_crypto causes buffer overflow. Remote exploitation of the… |
| CVE-2026-0640 | Alta (7.4) | 3.5% | — | 6 ene 2026 | A weakness has been identified in Tenda AC23 16.03.07.52. This affects the function sscanf of the file /goform/PowerSaveSet. Executing a manipulation of the argument Time can lead to buffer overflow. The attack can be… |
| CVE-2025-15217 | Alta (7.4) | 0.74% | — | 30 dic 2025 | A security flaw has been discovered in Tenda AC23 16.03.07.52. Affected is the function formSetPPTPUserList of the component HTTP POST Request Handler. Performing a manipulation of the argument list results in buffer… |
| CVE-2025-15216 | Alta (7.4) | 0.74% | — | 30 dic 2025 | A vulnerability was identified in Tenda AC23 16.03.07.52. This impacts the function fromSetIpMacBind of the file /goform/SetIpMacBind. Such manipulation of the argument bindnum leads to stack-based buffer overflow. It… |
| CVE-2025-12596 | Alta (7.4) | 1.2% | — | 2 nov 2025 | A security vulnerability has been detected in Tenda AC23 16.03.07.52. Affected is the function saveParentControlInfo of the file /goform/saveParentControlInfo. Such manipulation of the argument Time leads to buffer… |
| CVE-2025-12595 | Alta (7.4) | 1.1% | — | 2 nov 2025 | A weakness has been identified in Tenda AC23 16.03.07.52. This impacts the function formSetVirtualSer of the file /goform/SetVirtualServerCfg. This manipulation of the argument list causes buffer overflow. It is… |
| CVE-2025-11356 | Alta (7.4) | 0.80% | — | 7 oct 2025 | A vulnerability was found in Tenda AC23 up to 16.03.07.52. Affected by this issue is the function sscanf of the file /goform/SetStaticRouteCfg. The manipulation of the argument list results in buffer overflow. It is… |
| CVE-2025-10803 | Alta (7.4) | 0.80% | — | 22 sept 2025 | A vulnerability has been found in Tenda AC23 up to 16.03.07.52. Affected by this vulnerability is the function sscanf of the file /goform/SetPptpServerCfg of the component HTTP POST Request Handler. Such manipulation of… |
| CVE-2025-9605 | Alta (8.9) | 5.1% | — | 29 ago 2025 | A security vulnerability has been detected in Tenda AC21 and AC23 16.03.08.16. Affected is the function GetParentControlInfo of the file /goform/GetParentControlInfo. Such manipulation of the argument mac leads to… |
| CVE-2025-8060 | Alta (7.4) | 0.81% | — | 23 jul 2025 | A vulnerability has been found in Tenda AC23 16.03.07.52 and classified as critical. Affected by this vulnerability is the function sub_46C940 of the file /goform/setMacFilterCfg of the component httpd. The manipulation… |
| CVE-2025-3167 | Alta (7.1) | 0.88% | — | 3 abr 2025 | A vulnerability, which was classified as problematic, has been found in Tenda AC23 16.03.07.52. This issue affects some unknown processing of the file /goform/VerAPIMant of the component API Interface. The manipulation… |
| CVE-2023-24334 | Alta (8) | 0.49% | — | 21 feb 2024 | A stack overflow vulnerability in Tenda AC23 with firmware version US_AC23V1.0re_V16.03.07.45_cn_TDC01 allows attackers to run arbitrary commands via schedStartTime parameter. |
| CVE-2023-40798 | Alta (8.8) | 0.95% | — | 25 ago 2023 | In Tenda AC23 v16.03.07.45_cn, the formSetIPv6status and formGetWanParameter functions do not authenticate user input parameters, resulting in a post-authentication stack overflow vulnerability. |
| CVE-2023-40797 | Alta (8.8) | 0.95% | — | 25 ago 2023 | In Tenda AC23 v16.03.07.45_cn, the sub_4781A4 function does not validate the parameters entered by the user, resulting in a post-authentication stack overflow vulnerability. |
| CVE-2023-40802 | Media (6.5) | 0.81% | — | 25 ago 2023 | The get_parentControl_list_Info function does not verify the parameters entered by the user, causing a post-authentication heap overflow vulnerability in Tenda AC23 v16.03.07.45_cn |
| CVE-2023-40800 | Alta (8.8) | 0.95% | — | 25 ago 2023 | The compare_parentcontrol_time function does not authenticate user input parameters, resulting in a post-authentication stack overflow vulnerability in Tenda AC23 v16.03.07.45_cn. |
| CVE-2023-40799 | Crítica (9.8) | 0.93% | — | 25 ago 2023 | Tenda AC23 Vv16.03.07.45_cn is vulnerable to Buffer Overflow via sub_450A4C function. |
| CVE-2023-2649 | Alta (8.8) | 9.7% | — | 11 may 2023 | A vulnerability was found in Tenda AC23 16.03.07.45_cn. It has been declared as critical. This vulnerability affects unknown code of the file /bin/ate of the component Service Port 7329. The manipulation of the argument… |
| CVE-2023-0782 | Crítica (9.8) | 1.5% | — | 11 feb 2023 | A vulnerability was found in Tenda AC23 16.03.07.45 and classified as critical. Affected by this issue is the function formSetSysToolDDNS/formGetSysToolDDNS of the file /bin/httpd. The manipulation leads to… |
| CVE-2022-43108 | Crítica (9.8) | 0.97% | — | 3 nov 2022 | Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the firewallEn parameter in the formSetFirewallCfg function. |
| CVE-2022-43107 | Crítica (9.8) | 0.97% | — | 3 nov 2022 | Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the time parameter in the setSmartPowerManagement function. |
| CVE-2022-43106 | Crítica (9.8) | 0.97% | — | 3 nov 2022 | Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the schedStartTime parameter in the setSchedWifi function. |
| CVE-2022-43105 | Crítica (9.8) | 0.97% | — | 3 nov 2022 | Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the shareSpeed parameter in the fromSetWifiGusetBasic function. |
| CVE-2022-43104 | Crítica (9.8) | 0.97% | — | 3 nov 2022 | Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the wpapsk_crypto parameter in the fromSetWirelessRepeat function. |
| CVE-2022-43103 | Crítica (9.8) | 0.97% | — | 3 nov 2022 | Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the list parameter in the formSetQosBand function. |
| CVE-2022-43102 | Crítica (9.8) | 0.97% | — | 3 nov 2022 | Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the timeZone parameter in the fromSetSysTime function. |
| CVE-2022-43101 | Crítica (9.8) | 0.97% | — | 3 nov 2022 | Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the devName parameter in the formSetDeviceName function. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.