CVE-2025-9523

Severity CVSS v4.0:
HIGH
Type:
CWE-119 Buffer Errors
Publication date:
27/08/2025
Last modified:
20/09/2025

Description

A vulnerability was detected in Tenda AC1206 15.03.06.23. Affected is the function GetParentControlInfo of the file /goform/GetParentControlInfo. The manipulation of the argument mac results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit is now public and may be used.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:tenda:ac1206_firmware:15.03.06.23:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ac1206:-:*:*:*:*:*:*:*