CVE-2025-12595: Tenda AC23 SetVirtualServerCfg formSetVirtualSer buffer overflow
A weakness has been identified in Tenda AC23 16.03.07.52. This impacts the function formSetVirtualSer of the file /goform/SetVirtualServerCfg. This manipulation of the argument list causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12595?
CVE-2025-12595 is considered a high severity vulnerability due to its potential for remote exploitation and buffer overflow.
How do I fix CVE-2025-12595?
To fix CVE-2025-12595, update the Tenda AC23 firmware to the latest version provided by the manufacturer.
What type of vulnerability is CVE-2025-12595?
CVE-2025-12595 is a buffer overflow vulnerability that can be exploited remotely.
Which products are affected by CVE-2025-12595?
CVE-2025-12595 affects the Tenda AC23 router specifically running firmware version 16.03.07.52.
Can CVE-2025-12595 be exploited remotely?
Yes, CVE-2025-12595 can be exploited remotely, allowing attackers to potentially take control of the affected device.