CVE-2023-40802: Tenda AC23 Firmware

Medium severity, CVSS 6.5. EPSS: 0.8% chance of exploitation in the next 30 days.

The get_parentControl_list_Info function does not verify the parameters entered by the user, causing a post-authentication heap overflow vulnerability in Tenda AC23 v16.03.07.45_cn

Affected products

  • Tenda AC23 Firmware: version 16.03.07.45_cn only

Published 2023-08-25. Last modified 2026-06-17.