📦 Ch22 Firmware

by Tenda

🔍 What is Ch22 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-11423

CRITICAL CVSS 9.8 Oct 8, 2025

This vulnerability in Tenda CH22 routers allows remote attackers to execute arbitrary code or cause denial of service through memory corruption. Attackers can exploit this without authentication by ma...

CVE-2025-11418

CRITICAL CVSS 9.8 Oct 8, 2025

This is a critical stack-based buffer overflow vulnerability in Tenda CH22 routers that allows remote attackers to execute arbitrary code or crash the device. The vulnerability exists in the HTTP requ...

CVE-2024-46044

CRITICAL CVSS 9.8 Sep 13, 2024

CVE-2024-46044 is a critical stack overflow vulnerability in Tenda CH22 routers that allows remote attackers to execute arbitrary code by sending specially crafted requests to the affected function. T...

CVE-2025-15076

HIGH CVSS 7.3 Dec 25, 2025

This vulnerability allows remote attackers to bypass authentication and perform path traversal attacks on Tenda CH22 routers. Attackers can access restricted files and directories without proper crede...

CVE-2025-14526

HIGH CVSS 8.8 Dec 11, 2025

A buffer overflow vulnerability in Tenda CH22 router firmware version 1.0.0.1 allows remote attackers to execute arbitrary code by manipulating the 'page' parameter in the frmL7ImForm function. This a...

CVE-2025-13400

HIGH CVSS 8.8 Nov 19, 2025

A buffer overflow vulnerability in Tenda CH22 routers allows remote attackers to execute arbitrary code by manipulating the chkHz parameter in the formWrlExtraGet function. This affects Tenda CH22 rou...

CVE-2025-13288

HIGH CVSS 8.8 Nov 17, 2025

A buffer overflow vulnerability in Tenda CH22 routers allows remote attackers to execute arbitrary code by manipulating the 'delno' parameter in the PPTPUserSetting function. This affects Tenda CH22 r...

CVE-2025-12273

HIGH CVSS 8.8 Oct 27, 2025

CVE-2025-12273 is a buffer overflow vulnerability in Tenda CH22 routers affecting version 1.0.0.1. Attackers can remotely exploit this by manipulating the 'page' parameter in the webExcptypemanFilter ...

CVE-2025-12274

HIGH CVSS 8.8 Oct 27, 2025

A buffer overflow vulnerability in Tenda CH22 router firmware version 1.0.0.1 allows remote attackers to execute arbitrary code by manipulating the 'page' parameter in the fromP2pListFilter function. ...

CVE-2025-12271

HIGH CVSS 8.8 Oct 27, 2025

A buffer overflow vulnerability in Tenda CH22 router firmware version 1.0.0.1 allows remote attackers to execute arbitrary code by manipulating the 'page' parameter in the fromRouteStatic function. Th...

CVE-2025-12265

HIGH CVSS 8.8 Oct 27, 2025

A buffer overflow vulnerability in Tenda CH22 router firmware version 1.0.0.1 allows remote attackers to execute arbitrary code by manipulating the 'page' parameter in the fromVirtualSer function. Thi...

CVE-2025-12233

HIGH CVSS 8.8 Oct 27, 2025

A buffer overflow vulnerability in Tenda CH22 routers allows remote attackers to execute arbitrary code by manipulating the 'page' parameter in the fromSafeUrlFilter function. This affects Tenda CH22 ...

CVE-2025-12235

HIGH CVSS 8.0 Oct 27, 2025

A buffer overflow vulnerability in Tenda CH22 router firmware version 1.0.0.1 allows attackers on the local network to execute arbitrary code by manipulating the 'page' parameter in the fromSetIpBind ...

CVE-2025-12236

HIGH CVSS 8.8 Oct 27, 2025

A buffer overflow vulnerability in Tenda CH22 routers allows remote attackers to execute arbitrary code by manipulating the 'page' parameter in the DHCP client list function. This affects Tenda CH22 r...

CVE-2025-11117

HIGH CVSS 8.8 Sep 28, 2025

A buffer overflow vulnerability in Tenda CH22 router firmware version 1.0.0.1 allows remote attackers to execute arbitrary code or cause denial of service by sending specially crafted requests to the ...

CVE-2025-9813

HIGH CVSS 8.8 Sep 2, 2025

A buffer overflow vulnerability in Tenda CH22 router firmware allows remote attackers to execute arbitrary code or crash the device by sending specially crafted requests to the /goform/SetSambaConf en...

CVE-2025-9748

HIGH CVSS 8.8 Aug 31, 2025

A stack-based buffer overflow vulnerability exists in Tenda CH22 router firmware version 1.0.0.1. Remote attackers can exploit this by sending specially crafted requests to the httpd component's /gofo...

CVE-2025-9443

HIGH CVSS 8.8 Aug 26, 2025

A buffer overflow vulnerability in Tenda CH22 routers allows remote attackers to execute arbitrary code by manipulating the new_account parameter in the formeditUserName function. This affects Tenda C...

CVE-2025-9006

HIGH CVSS 8.8 Aug 15, 2025

A buffer overflow vulnerability in Tenda CH22 router firmware version 1.0.0.1 allows remote attackers to execute arbitrary code by exploiting the formdelFileName function. This affects all users of Te...

CVE-2025-8180

HIGH CVSS 8.8 Jul 26, 2025

A critical buffer overflow vulnerability in Tenda CH22 routers allows remote attackers to execute arbitrary code by manipulating the 'old_account' parameter in the formdeleteUserName function. This af...

CVE-2025-5685

HIGH CVSS 8.8 Jun 5, 2025

A critical stack-based buffer overflow vulnerability in Tenda CH22 routers allows remote attackers to execute arbitrary code by manipulating the 'page' parameter in the formNatlimit function. This aff...

CVE-2025-5619

HIGH CVSS 8.8 Jun 4, 2025

A critical stack-based buffer overflow vulnerability in Tenda CH22 routers allows remote attackers to execute arbitrary code by manipulating the Password parameter in the formaddUserName function. Thi...

CVE-2025-15229

MEDIUM CVSS 5.3 Dec 30, 2025

A buffer overflow vulnerability in Tenda CH22 routers allows remote attackers to cause denial of service by manipulating the LISTLEN parameter in the fromDhcpListClient function. This affects Tenda CH...