A security flaw has been discovered in Tenda CH22 1.0.0.1. This affects the function frmL7ImForm of the file /goform/L7Im. Performing manipulation of the argument page results in buffer overflow. Remote exploitation of the attack is possible. The exploit has been released to the public and may be exploited.
Metrics
Affected Vendors & Products
References
History
Fri, 19 Dec 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tenda ch22 Firmware
|
|
| CPEs | cpe:2.3:h:tenda:ch22:-:*:*:*:*:*:*:* cpe:2.3:o:tenda:ch22_firmware:1.0.0.1:*:*:*:*:*:*:* |
|
| Vendors & Products |
Tenda ch22 Firmware
|
Thu, 11 Dec 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tenda
Tenda ch22 |
|
| Vendors & Products |
Tenda
Tenda ch22 |
Thu, 11 Dec 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security flaw has been discovered in Tenda CH22 1.0.0.1. This affects the function frmL7ImForm of the file /goform/L7Im. Performing manipulation of the argument page results in buffer overflow. Remote exploitation of the attack is possible. The exploit has been released to the public and may be exploited. | |
| Title | Tenda CH22 L7Im frmL7ImForm buffer overflow | |
| Weaknesses | CWE-119 CWE-120 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-12-11T16:32:09.328Z
Updated: 2025-12-11T16:32:09.328Z
Reserved: 2025-12-11T08:24:15.841Z
Link: CVE-2025-14526
No data.
Status : Analyzed
Published: 2025-12-11T17:15:55.660
Modified: 2025-12-19T14:41:24.493
Link: CVE-2025-14526
No data.