CVE-2025-12596: Tenda AC23 saveParentControlInfo buffer overflow
A security vulnerability has been detected in Tenda AC23 16.03.07.52. Affected is the function saveParentControlInfo of the file /goform/saveParentControlInfo. Such manipulation of the argument Time leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12596?
CVE-2025-12596 is classified as a high severity vulnerability due to the potential for remote exploitation.
How do I fix CVE-2025-12596?
To mitigate CVE-2025-12596, update your Tenda AC23 firmware to the latest version provided by the vendor.
What systems are affected by CVE-2025-12596?
CVE-2025-12596 affects the Tenda AC23 router running firmware version 16.03.07.52.
What type of vulnerability is CVE-2025-12596?
CVE-2025-12596 is a buffer overflow vulnerability that can be exploited through the saveParentControlInfo function.
Can CVE-2025-12596 be exploited remotely?
Yes, CVE-2025-12596 can be exploited remotely, allowing an attacker to manipulate the Time argument.