Junglewise Threat Intelligence

CVE-2026-15543: Tenda CH22 buffer overflow in formCertListInfo

CVE-2026-15543 · Severity: high · CVSS 8.8 · Published 2026-07-13

Technologies: Tenda CH22. Vendors: Tenda.

Executive brief

A vulnerability exists in the Tenda CH22 router that could allow an attacker to disrupt or take control of the device. By sending a specially crafted request to the device's management interface, an attacker can cause a system crash or potentially execute unauthorized commands. This could lead to a total loss of network availability or unauthorized access to data passing through the router.

Technical details

A stack-based buffer overflow vulnerability exists in the Tenda CH22 router, specifically within the 'formCertListInfo' function located in the '/goform/CertListInfo' file. The vulnerability is triggered by improper validation of the 'Name' argument, allowing an attacker to overwrite memory. This attack can be launched remotely by an authenticated user (PR:L). Successful exploitation can lead to arbitrary code execution or a complete denial of service (DoS) of the device. Public exploit code is reportedly available, increasing the risk of exploitation.

Affected products

  • Tenda CH22 1.0.0.1

Timeline

  • 2026-07-13: disclosed: Vulnerability disclosed via VulDB and NVD

References

Related threats