CVE-2026-0640
Severity CVSS v4.0:
HIGH
Type:
CWE-119
Buffer Errors
Publication date:
06/01/2026
Last modified:
06/01/2026
Description
A weakness has been identified in Tenda AC23 16.03.07.52. This affects the function sscanf of the file /goform/PowerSaveSet. Executing a manipulation of the argument Time can lead to buffer overflow. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.
Impact
Base Score 4.0
7.40
Severity 4.0
HIGH
Base Score 3.x
8.80
Severity 3.x
HIGH
Base Score 2.0
9.00
Severity 2.0
HIGH
References to Advisories, Solutions, and Tools
- https://github.com/xyh4ck/iot_poc/blob/main/Tenda%20AC23_Buffer_Overflow/Tenda%20AC23_Buffer_Overflow.md
- https://github.com/xyh4ck/iot_poc/blob/main/Tenda%20AC23_Buffer_Overflow/Tenda%20AC23_Buffer_Overflow.md#poc
- https://vuldb.com/?ctiid_339683=
- https://vuldb.com/?id_339683=
- https://vuldb.com/?submit_731772=
- https://www.tenda.com.cn/



