CVE-2026-0640: Tenda AC23 PowerSaveSet sscanf buffer overflow
A weakness has been identified in Tenda AC23 16.03.07.52. This affects the function sscanf of the file /goform/PowerSaveSet. Executing a manipulation of the argument Time can lead to buffer overflow. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0640?
CVE-2026-0640 is classified as a critical vulnerability due to its potential for remote exploitation leading to a buffer overflow.
How do I fix CVE-2026-0640?
To mitigate CVE-2026-0640, update your Tenda AC23 router firmware to the latest version provided by the manufacturer.
What could an attacker achieve by exploiting CVE-2026-0640?
An attacker exploiting CVE-2026-0640 can execute arbitrary code remotely, compromising the affected Tenda AC23 router.
Who is affected by CVE-2026-0640?
CVE-2026-0640 affects users of the Tenda AC23 router running version 16.03.07.52.
Is CVE-2026-0640 being actively exploited?
Yes, CVE-2026-0640 is known to have available exploits, making it essential to apply security patches promptly.