CVE-2025-15217
8.8Tenda · AC23
A buffer overflow vulnerability in the Tenda AC23 router allows remote attackers to execute code via manipulation of the formSetPPTPUserList function.
Executive summary
A critical buffer overflow vulnerability in the Tenda AC23 router enables remote memory corruption and potential code execution for authenticated users.
Vulnerability
This vulnerability is a buffer overflow (CWE-120) triggered by manipulating the argument list within the formSetPPTPUserList function of the HTTP POST request handler, requiring low-privileged authenticated access.
Business impact
The exploitation of this vulnerability leads to total memory corruption, which can result in unauthorized code execution or complete system compromise of the affected network device. Given the CVSS score of 8.8, this flaw poses a high risk to business operations, potentially allowing attackers to pivot into the internal network, intercept traffic, or cause persistent denial of service.
Remediation
Immediate Action: Contact the vendor or monitor the official Tenda support website for firmware updates addressing the reported memory corruption in version 16.03.07.52.
Proactive Monitoring: Review administrative access logs for unusual HTTP POST requests directed at the PPTP user configuration endpoints and monitor device stability for unexpected reboots.
Compensating Controls: Restrict administrative access to the router web interface to trusted management IP addresses and disable remote management features until a patch is applied.
Exploitation status
Public Exploit Available: Yes — a technical write-up containing the attack mechanism is available via the linked research documentation.
Analyst recommendation
The severity of this flaw necessitates immediate attention to mitigate the risk of remote code execution. Security teams should prioritize restricting network access to the management interface of the affected Tenda AC23 devices and apply the necessary firmware updates as soon as they are made available by the manufacturer.
More Tenda CVEs
Sources
Originally found and disclosed by wxhwxhwxh_tutu (VulDB User), per the CVE Program record.
- VDB-338602 | Tenda AC23 HTTP POST Request formSetPPTPUserList buffer overflow Vulnerability database entry
- VDB-338602 | CTI Indicators (IOB, IOC, IOA)
- Submit #725448 | Tenda AC23 AC23 V16.03.07.52 Buffer Overflow Third-party advisory
- Related
- tenda.com.cn