CVE-2025-15217

Severity CVSS v4.0:
HIGH
Type:
CWE-119 Buffer Errors
Publication date:
30/12/2025
Last modified:
24/02/2026

Description

A security flaw has been discovered in Tenda AC23 16.03.07.52. Affected is the function formSetPPTPUserList of the component HTTP POST Request Handler. Performing a manipulation of the argument list results in buffer overflow. The attack can be initiated remotely.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:tenda:ac23_firmware:16.03.07.52:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ac23:-:*:*:*:*:*:*:*