CVE-2025-11356: Tenda AC23 SetStaticRouteCfg sscanf buffer overflow
A vulnerability was found in Tenda AC23 up to 16.03.07.52. Affected by this issue is the function sscanf of the file /goform/SetStaticRouteCfg. The manipulation of the argument list results in buffer overflow. It is possible to launch the attack remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11356?
CVE-2025-11356 is considered a high-severity vulnerability due to its potential to allow remote buffer overflow exploits.
How do I fix CVE-2025-11356?
To fix CVE-2025-11356, update the Tenda AC23 firmware to a version later than 16.03.07.52.
Can CVE-2025-11356 be exploited remotely?
Yes, CVE-2025-11356 can be exploited remotely, allowing attackers to execute arbitrary code.
Which devices are affected by CVE-2025-11356?
The Tenda AC23 router with firmware version up to 16.03.07.52 is affected by CVE-2025-11356.
What type of vulnerability is CVE-2025-11356?
CVE-2025-11356 is a buffer overflow vulnerability that affects the sscanf function in the Tenda AC23 router.