Executive brief
A security vulnerability has been identified in the Tenda CH22, a networking device. An attacker could exploit this flaw to cause the device to crash or potentially take full control of it by sending a specially crafted web request. This could lead to a total loss of network availability or unauthorized access to data passing through the device.
Technical details
A stack-based buffer overflow vulnerability exists in the Tenda CH22 firmware version 1.0.0.1. The flaw is located within the 'formWebTypeLibrary' function in the '/goform/webtypelibrary' component of the Parameter Handler. The root cause is an unsafe 'strcat' operation on the user-provided 'webSiteId' parameter without adequate length validation. A remote attacker with low privileges can trigger this overflow by sending a crafted POST request, potentially leading to remote code execution (RCE) or a denial of service (DoS) condition. A proof-of-concept exploit has been publicly disclosed.
Affected products
- Tenda CH22 1.0.0.1
Timeline
- 2026-03-31: disclosed: Vulnerability disclosed and CVE assigned
- 2026-03-31: advisory: Initial advisory published by VulDB