CVE List

CVE-2025-11356

Critical 8.8

A vulnerability was found in Tenda AC23 up to 16.03.07.52. Affected by this issue is the function sscanf of the file /goform/SetStaticRouteCfg. The manipulation of the argument list results in buffer overflow. It is possible to launch the attack remotely. The exploit has been made public and could be used.

Published October 7, 2025.

Affected software

Get alerts for Tenda Ac23 Firmware

Reference links