CVE-2025-15217

A security flaw has been discovered in Tenda AC23 16.03.07.52. Affected is the function formSetPPTPUserList of the component HTTP POST Request Handler. Performing a manipulation of the argument list results in buffer overflow. The attack can be initiated remotely.

high 8.8 CVSS 3.1
Published: Dec 30, 2025
Modified: Feb 24, 2026
Vendor: Tenda
Product: Ac23 Firmware
Versions: 16.03.07.52

Description

A security flaw has been discovered in Tenda AC23 16.03.07.52. Affected is the function formSetPPTPUserList of the component HTTP POST Request Handler. Performing a manipulation of the argument list results in buffer overflow. The attack can be initiated remotely.

References

Related CVEs