Executive brief
A security vulnerability exists in the Tenda CH22, a networking device. An attacker can exploit this flaw to crash the device or potentially take full control of it by sending a specially crafted web request. This could lead to a complete loss of service or unauthorized access to the network traffic managed by the device.
Technical details
A stack-based buffer overflow vulnerability exists in the 'formCertLocalPrecreate' function within the '/goform/CertLocalPrecreate' endpoint of Tenda CH22 firmware version 1.0.0.1. The root cause is the unsafe use of the 'sprintf' function, which processes the user-supplied 'standard' parameter without adequate length validation, allowing the stack-based buffer 's' to be overwritten. A remote attacker with low privileges can exploit this by sending a crafted POST request. Successful exploitation can lead to a Denial of Service (DoS) or Remote Code Execution (RCE). A public Proof of Concept (PoC) has been released.
Affected products
- Tenda CH22 1.0.0.1
Timeline
- 2026-04-05: disclosed
- 2026-04-05: advisory