Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-26203 | A security vulnerability has been detected in Tenda AC21 and AC23 16.03.08.16. Affected is the function GetParentControlInfo of the file /goform/GetParentControlInfo. Such manipulation of the argument mac leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. |
Wed, 03 Sep 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tenda ac21 Firmware
Tenda ac23 Firmware |
|
| CPEs | cpe:2.3:h:tenda:ac21:-:*:*:*:*:*:*:* cpe:2.3:h:tenda:ac23:-:*:*:*:*:*:*:* cpe:2.3:o:tenda:ac21_firmware:16.03.08.16:*:*:*:*:*:*:* cpe:2.3:o:tenda:ac23_firmware:16.03.08.16:*:*:*:*:*:*:* |
|
| Vendors & Products |
Tenda ac21 Firmware
Tenda ac23 Firmware |
Sun, 31 Aug 2025 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tenda
Tenda ac21 Tenda ac23 |
|
| Vendors & Products |
Tenda
Tenda ac21 Tenda ac23 |
Fri, 29 Aug 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 29 Aug 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in Tenda AC21 and AC23 16.03.08.16. Affected is the function GetParentControlInfo of the file /goform/GetParentControlInfo. Such manipulation of the argument mac leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. | |
| Title | Tenda AC21/AC23 GetParentControlInfo stack-based overflow | |
| Weaknesses | CWE-119 CWE-121 |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-08-29T13:31:06.430Z
Reserved: 2025-08-28T15:21:33.747Z
Link: CVE-2025-9605
Updated: 2025-08-29T13:30:55.570Z
Status : Analyzed
Published: 2025-08-29T03:15:40.140
Modified: 2025-09-03T16:10:04.083
Link: CVE-2025-9605
No data.
OpenCVE Enrichment
Updated: 2025-08-31T08:41:39Z
EUVD