๐Ÿ” CVE Alert

CVE-2025-15217

HIGH 8.8

Tenda AC23 HTTP POST Request formSetPPTPUserList buffer overflow

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

A security flaw has been discovered in Tenda AC23 16.03.07.52. Affected is the function formSetPPTPUserList of the component HTTP POST Request Handler. Performing a manipulation of the argument list results in buffer overflow. The attack can be initiated remotely.

CWE CWE-120 CWE-119
Vendor tenda
Product ac23
Published Dec 30, 2025
Last Updated Feb 24, 2026
Stay Ahead of the Next One

Get instant alerts for tenda ac23

Be the first to know when new high vulnerabilities affecting tenda ac23 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Tenda / AC23
16.03.07.52

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/?id.338602 vuldb.com: https://vuldb.com/?ctiid.338602 vuldb.com: https://vuldb.com/?submit.725448 lavender-bicycle-a5a.notion.site: https://lavender-bicycle-a5a.notion.site/Tenda-AC23-formSetPPTPUserList-2d753a41781f8091b772cf9e66a687f1?source=copy_link tenda.com.cn: https://www.tenda.com.cn/ lavender-bicycle-a5a.notion.site: https://lavender-bicycle-a5a.notion.site/Tenda-AC23-formSetPPTPUserList-2d753a41781f8091b772cf9e66a687f1

Credits

๐Ÿ” wxhwxhwxh_tutu (VulDB User)