CVE-2025-15216

8.8

Tenda · AC23

A stack-based buffer overflow in the Tenda AC23 SetIpMacBind function allows remote attackers to trigger memory corruption via the bindnum argument.

Executive summary

A critical stack-based buffer overflow vulnerability in Tenda AC23 firmware version 16.03.07.52 poses a severe risk of remote code execution or system instability.

Vulnerability

This vulnerability is a stack-based buffer overflow occurring in the SetIpMacBind function within the /goform/SetIpMacBind file. An attacker with low-level privileges can trigger this memory corruption remotely by manipulating the bindnum argument.

Business impact

Successful exploitation of this vulnerability can lead to a complete compromise of the affected router, potentially resulting in unauthorized network access, data interception, or a total denial of service. With a CVSS score of 8.8, this flaw represents a high risk to organizational security, as the device acts as a primary entry point to the internal network.

Remediation

Immediate Action: Contact the vendor for a security update or firmware patch addressing this buffer overflow, as no official fix is currently listed. If no update is available, restrict access to the device management interface to trusted administrative subnets only.

Proactive Monitoring: Monitor network traffic for unusual POST requests directed at the /goform/SetIpMacBind endpoint. Review system logs for signs of device reboots or process crashes that may indicate exploitation attempts.

Compensating Controls: Deploy a Web Application Firewall (WAF) or an Intrusion Prevention System (IPS) to inspect and block malformed packets targeting the specific vulnerable function. Ensure the device management interface is not exposed to the public internet.

Exploitation status

Public Exploit Available: Yes — a published proof-of-concept exists as documented in the security researcher's write-up.

Analyst recommendation

Given the existence of a public proof-of-concept and the high CVSS score, this vulnerability should be prioritized for mitigation. Administrators must isolate the affected hardware from untrusted networks immediately while awaiting a vendor-supplied firmware update to permanently remediate the memory corruption flaw.

More Tenda CVEs

Sources

Originally found and disclosed by yhryhryhr_miemie (VulDB User), per the CVE Program record.