CVE-2025-9813
8.8Tenda · CH22
A buffer overflow vulnerability in Tenda CH22 version 1.0.0.1 allows remote attackers to trigger memory corruption via the samba_userNameSda argument in the /goform/SetSambaConf function.
Executive summary
A critical buffer overflow vulnerability in Tenda CH22 routers allows remote execution of unauthorized actions, posing a significant risk of device compromise.
Vulnerability
This is a memory corruption flaw, specifically a buffer overflow, occurring within the formSetSambaConf function of the /goform/SetSambaConf endpoint. The vulnerability is exploitable remotely by an authenticated user via the manipulation of the samba_userNameSda parameter.
Business impact
The ability to trigger a buffer overflow in network infrastructure hardware can lead to full system compromise, including unauthorized configuration changes or complete device denial of service. Given the CVSS score of 8.8, this vulnerability represents a high risk to business continuity and network integrity, potentially allowing attackers to pivot into the internal network if the device is successfully exploited.
Remediation
Immediate Action: Since no official patch is currently identified, administrators should restrict access to the device management interface to trusted internal networks only and disable the Samba service if it is not strictly required for business operations.
Proactive Monitoring: Security teams should monitor device logs for unusual traffic patterns directed at the /goform/SetSambaConf endpoint and investigate any unexpected system reboots or service crashes.
Compensating Controls: Deploy a Web Application Firewall or network-based Intrusion Prevention System (IPS) rule to inspect and block malformed requests targeting the samba_userNameSda parameter.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the research write-up at https://github.com/csgii/cve/issues/2.
Analyst recommendation
Due to the severity of this remote memory corruption vulnerability and the existence of a public proof-of-concept, users are urged to prioritize the hardening of Tenda CH22 devices. Administrators must minimize the attack surface by isolating the device management interface and should actively monitor vendor channels for the release of an official firmware patch to permanently remediate this flaw.
More Tenda CVEs
Sources
Originally found and disclosed by wakaka123 (VulDB User), per the CVE Program record.
- VDB-322140 | Tenda CH22 SetSambaConf formSetSambaConf buffer overflow Vulnerability database entry
- VDB-322140 | CTI Indicators (IOB, IOC, IOA)
- Submit #641151 | Tenda CH22 V1.0.0.1 Buffer Overflow Third-party advisory
- Exploit / PoC
- tenda.com.cn