CVE-2025-9006

A vulnerability was identified in Tenda CH22 1.0.0.1. Affected by this vulnerability is the function formdelFileName of the file /goform/delFileName. The manipulation leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVSS

No CVSS.

References
Link Resource
https://github.com/moweizhang1994/cve/issues/2 Exploit Issue Tracking Third Party Advisory
https://github.com/moweizhang1994/cve/issues/2 Exploit Issue Tracking Third Party Advisory
https://vuldb.com/?ctiid.320035 Permissions Required
https://vuldb.com/?id.320035 Third Party Advisory VDB Entry
https://vuldb.com/?submit.628845 Third Party Advisory VDB Entry
https://www.tenda.com.cn/ Product
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tenda:ch22_firmware:1.0.0.1:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ch22:-:*:*:*:*:*:*:*

History

18 Aug 2025, 19:15

Type Values Removed Values Added
CWE CWE-120
CWE-119
CVSS v2 : unknown
v3 : 8.8
v2 : unknown
v3 : unknown
References () https://github.com/moweizhang1994/cve/issues/2 - Exploit, Third Party Advisory, Issue Tracking () https://github.com/moweizhang1994/cve/issues/2 - Exploit, Issue Tracking, Third Party Advisory

18 Aug 2025, 15:11

Type Values Removed Values Added
First Time Tenda ch22 Firmware
Tenda ch22
Tenda
References () https://www.tenda.com.cn/ - () https://www.tenda.com.cn/ - Product
References () https://vuldb.com/?submit.628845 - () https://vuldb.com/?submit.628845 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?id.320035 - () https://vuldb.com/?id.320035 - Third Party Advisory, VDB Entry
References () https://github.com/moweizhang1994/cve/issues/2 - () https://github.com/moweizhang1994/cve/issues/2 - Exploit, Third Party Advisory, Issue Tracking
References () https://vuldb.com/?ctiid.320035 - () https://vuldb.com/?ctiid.320035 - Permissions Required
CPE cpe:2.3:o:tenda:ch22_firmware:1.0.0.1:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ch22:-:*:*:*:*:*:*:*

15 Aug 2025, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-15 03:15

Updated : 2025-08-18 19:15


NVD link : CVE-2025-9006

Mitre link : CVE-2025-9006


JSON object : View

Products Affected

tenda

  • ch22
  • ch22_firmware
CWE

No CWE.