Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-10803

Опубликовано: 22 сент. 2025
Источник: nvd
CVSS3: 8.8
CVSS2: 9
EPSS Низкий

Описание

A vulnerability has been found in Tenda AC23 up to 16.03.07.52. Affected by this vulnerability is the function sscanf of the file /goform/SetPptpServerCfg of the component HTTP POST Request Handler. Such manipulation of the argument startIp leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:tenda:ac23_firmware:*:*:*:*:*:*:*:*
Версия до 16.03.07.52 (включая)
cpe:2.3:h:tenda:ac23:1.0:*:*:*:*:*:*:*

EPSS

Процентиль: 34%
0.00138
Низкий

8.8 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 8.8
github
5 месяцев назад

A vulnerability has been found in Tenda AC23 up to 16.03.07.52. Affected by this vulnerability is the function sscanf of the file /goform/SetPptpServerCfg of the component HTTP POST Request Handler. Such manipulation of the argument startIp leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 8.8
fstec
5 месяцев назад

Уязвимость функции sscanf микропрограммного обеспечения маршрутизаторов Tenda AC23, позволяющая нарушителю выполнить произвольную команду

EPSS

Процентиль: 34%
0.00138
Низкий

8.8 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-119