CVE-2025-15217: Tenda AC23 HTTP POST Request formSetPPTPUserList buffer overflow
Published Dec 30, 2025
·Updated
A security flaw has been discovered in Tenda AC23 16.03.07.52. Affected is the function formSetPPTPUserList of the component HTTP POST Request Handler. Performing a manipulation of the argument list results in buffer overflow. The attack can be initiated remotely.
Affected Software
3 affected components
Tenda AC23
All of the following
Tenda Ac23 Firmware=16.03.07.52
Tenda AC23
Event History
Dec 30, 2025
CVE Published
via MITRE·03:02 AM
Data Sourced
via MITRE·03:02 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-15217?
CVE-2025-15217 is classified as a high-severity vulnerability due to the potential for remote exploitation.
2
How do I fix CVE-2025-15217?
To fix CVE-2025-15217, update the Tenda AC23 to the latest firmware version available from the vendor.
3
What type of vulnerability is CVE-2025-15217?
CVE-2025-15217 is a buffer overflow vulnerability found in the HTTP POST Request Handler component.
4
What products are affected by CVE-2025-15217?
CVE-2025-15217 specifically affects the Tenda AC23 router.
5
Can CVE-2025-15217 be exploited remotely?
Yes, CVE-2025-15217 can be exploited remotely by manipulating the argument list.