CVE-2025-15216: Tenda AC23 SetIpMacBind fromSetIpMacBind stack-based overflow
A vulnerability was identified in Tenda AC23 16.03.07.52. This impacts the function fromSetIpMacBind of the file /goform/SetIpMacBind. Such manipulation of the argument bindnum leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15216?
CVE-2025-15216 is rated as a high severity vulnerability due to its potential for remote exploitation via stack-based buffer overflow.
How do I fix CVE-2025-15216?
To mitigate CVE-2025-15216, users should update their Tenda AC23 devices to the latest firmware version available from Tenda.
What are the risks associated with CVE-2025-15216?
CVE-2025-15216 can allow an attacker to execute arbitrary code remotely, leading to unauthorized access or control over the affected device.
Is CVE-2025-15216 being actively exploited?
Yes, CVE-2025-15216 has been publicly disclosed and can potentially be actively exploited by attackers.
Which product is affected by CVE-2025-15216?
CVE-2025-15216 specifically impacts the Tenda AC23 device running version 16.03.07.52.