Description
A vulnerability was detected in Tenda CH22 1.0.0.1. Affected is the function formWrlExtraGet of the file /goform/WrlExtraGet. Performing manipulation of the argument chkHz results in buffer overflow. Remote exploitation of the attack is possible. The exploit is now public and may be used.
Problem types
Product status
Timeline
| 2025-11-19: | Advisory disclosed |
| 2025-11-19: | VulDB entry created |
| 2025-11-19: | VulDB entry last update |
Credits
Li Hu (VulDB User)
References
vuldb.com/?id.332926 (VDB-332926 | Tenda CH22 WrlExtraGet formWrlExtraGet buffer overflow)
vuldb.com/?ctiid.332926 (VDB-332926 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/?submit.692145 (Submit #692145 | Tenda CH22 V1.0.0.1 Buffer Overflow)
github.com/f000x0/cve/issues/14
www.tenda.com.cn/