Executive brief
A security vulnerability has been identified in the Tenda CH22 router, a device used for managing network connectivity. An attacker can exploit this flaw to crash the device or potentially take full control of it remotely. This could lead to a total loss of internet availability or the unauthorized interception of network traffic.
Technical details
A stack-based buffer overflow vulnerability exists in the httpd service of Tenda CH22 firmware version 1.0.0.1. The flaw is located within the formWrlExtraSet function in the /goform/WrlExtraSet component. The vulnerability is triggered when the 'GO' parameter is processed by the sub_396FC function; specifically, a lack of length validation allows a long string to overflow a stack buffer via a sprintf call. A remote attacker with low privileges can exploit this by sending a specially crafted POST request. Successful exploitation can lead to a Denial of Service (DoS) or Remote Code Execution (RCE). A public Proof of Concept (PoC) is available.
Affected products
- Tenda CH22 1.0.0.1
Timeline
- 2026-04-05: disclosed: Vulnerability reported to VulDB
- 2026-04-06: advisory: NVD advisory published