CVE-2025-9006
8.8Tenda · CH22
A buffer overflow vulnerability in the Tenda CH22 router allows remote attackers to trigger memory corruption via the formdelFileName function.
Executive summary
A critical buffer overflow vulnerability in Tenda CH22 firmware allows remote, authenticated attackers to execute arbitrary code or crash the system.
Vulnerability
This vulnerability originates from a buffer overflow in the formdelFileName function located in the /goform/delFileName file. The vulnerability is exploitable remotely by an authenticated user, leading to potential memory corruption or arbitrary code execution.
Business impact
The exploitation of this vulnerability could lead to a complete compromise of the affected network device, resulting in unauthorized access to internal network traffic or system downtime. Given the CVSS score of 8.8, this flaw represents a high risk to organizational security, as it allows attackers to gain control over infrastructure hardware.
Remediation
Immediate Action: Since a specific vendor patch is currently unknown, administrators should restrict network access to the management interface of the Tenda CH22 to trusted IP addresses only.
Proactive Monitoring: Monitor device logs for unusual activity related to the /goform/delFileName endpoint and investigate any unexpected system reboots or service instability.
Compensating Controls: Implement strict firewall rules to block external access to the device management interface, ensuring that only authorized internal administrative segments can communicate with the unit.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept exists, as documented in the research write-up at https://github.com/moweizhang1994/cve/issues/2.
Analyst recommendation
Organizations utilizing Tenda CH22 hardware must prioritize the mitigation of this vulnerability by isolating the device from untrusted network segments. While a formal patch remains unavailable, reducing the attack surface via network-level access controls is essential to prevent unauthorized exploitation of this critical memory corruption flaw.
More Tenda CVEs
Sources
Originally found and disclosed by moweizhang1994 (VulDB User), per the CVE Program record.
- VDB-320035 | Tenda CH22 delFileName formdelFileName buffer overflow Vulnerability database entry
- VDB-320035 | CTI Indicators (IOB, IOC, IOA)
- Submit #628845 | Tenda CH22 V1.0.0.1 Buffer Overflow Third-party advisory
- Exploit / PoC
- tenda.com.cn