Description
A security flaw has been discovered in Tenda AC23 16.03.07.52. Affected is the function formSetPPTPUserList of the component HTTP POST Request Handler. Performing a manipulation of the argument list results in buffer overflow. The attack can be initiated remotely.
Problem types
Product status
Timeline
| 2025-12-28: | Advisory disclosed |
| 2025-12-28: | VulDB entry created |
| 2026-01-03: | VulDB entry last update |
Credits
wxhwxhwxh_tutu (VulDB User)
References
lavender-bicycle-a5a.notion.site/...781f8091b772cf9e66a687f1
vuldb.com/?id.338602 (VDB-338602 | Tenda AC23 HTTP POST Request formSetPPTPUserList buffer overflow)
vuldb.com/?ctiid.338602 (VDB-338602 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/?submit.725448 (Submit #725448 | Tenda AC23 AC23 V16.03.07.52 Buffer Overflow)
lavender-bicycle-a5a.notion.site/...6a687f1?source=copy_link
www.tenda.com.cn/