CVE Tools

AC23 Firmware

27 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for AC23 Firmware, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.

AC23 Firmware CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
AC23 Firmware CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-041
2025-050
2025-060
2025-071
2025-081
2025-091
2025-101
2025-112
2025-122
2026-012
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 27 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical1037%
  • High1556%
  • Medium27%

Latest CVEs

The 15 most recently published vulnerabilities affecting AC23 Firmware.

  1. CVE-2026-1420Tenda AC23 WifiExtraSet buffer overflow8.8
  2. CVE-2026-0640Tenda AC23 PowerSaveSet sscanf buffer overflow8.8
  3. CVE-2025-15217Tenda AC23 HTTP POST Request formSetPPTPUserList buffer overflow8.8
  4. CVE-2025-15216Tenda AC23 SetIpMacBind fromSetIpMacBind stack-based overflow8.8
  5. CVE-2025-12596Tenda AC23 saveParentControlInfo buffer overflow8.8
  6. CVE-2025-12595Tenda AC23 SetVirtualServerCfg formSetVirtualSer buffer overflow8.8
  7. CVE-2025-11356Tenda AC23 SetStaticRouteCfg sscanf buffer overflow8.8
  8. CVE-2025-10803Tenda AC23 HTTP POST Request SetPptpServerCfg sscanf buffer overflow8.8
  9. CVE-2025-9605Tenda AC21/AC23 GetParentControlInfo stack-based overflow9.8
  10. CVE-2025-8060Tenda AC23 httpd setMacFilterCfg sub_46C940 stack-based overflow8.8
  11. CVE-2025-3167Tenda AC23 API Interface VerAPIMant denial of service6.5
  12. CVE-2023-24334A stack overflow vulnerability in Tenda AC23 with firmware version US_AC23V1.0re_V16.03.07.45_cn_TDC01 allows attackers to run arbitrary commands via schedStartTime parameter.8.0
  13. CVE-2023-40797In Tenda AC23 v16.03.07.45_cn, the sub_4781A4 function does not validate the parameters entered by the user, resulting in a post-authentication stack overflow vulnerability.8.8
  14. CVE-2023-40802The get_parentControl_list_Info function does not verify the parameters entered by the user, causing a post-authentication heap overflow vulnerability in Tenda AC23 v16.03.07.45_cn6.5
  15. CVE-2023-40799Tenda AC23 Vv16.03.07.45_cn is vulnerable to Buffer Overflow via sub_450A4C function.9.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store