CVE Details
Basic Information
| Title |
Tenda CH22 addUserName formaddUserName stack-based overflow |
| Type |
cve |
| Published |
2025-06-04T23:00:24.208Z |
| Last Seen |
|
Product Information
| Vendor |
Tenda |
| Product |
CH22 |
| Version |
1.0.0.1 |
CVSS Information
| Base Score |
8.7 (HIGH) |
| Attack Vector |
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| Confidentiality Impact |
|
| Integrity Impact |
|
| Availability Impact |
|
AI Analysis
| AI Description |
A critical buffer overflow vulnerability in the Tenda CH22 router (version 1.0.0.1) allows remote attackers to execute arbitrary code via the formaddUserName function. The CVSS score of 8.7 indicates a high severity, and the exploit is publicly disclosed. |
| AI Severity |
Critical |
| Vendor |
Tenda |
| Product |
Tenda CH22 |
| Affected Version |
1.0.0.1 |
Additional Information
| CVE List |
|
| CWE List |
CWE-121, CWE-119 |
| Bulletin Family |
|
| Source Data |
Tenda CH22 1.0.0.1 |
Source Information
| Source Data |
Tenda CH22 1.0.0.1 |
| Source Link |
|
Description
A vulnerability, which was classified as critical, has been found in Tenda CH22 1.0.0.1. This issue affects the function formaddUserName of the file /goform/addUserName. The manipulation of the argument Password leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVSS Score Summary
View Full CVE Details