Tenda
Tenda Ch22 Firmware: vulnerabilidades y CVE
Tenda Ch22 Firmware tiene 39 vulnerabilidades publicadas, 27 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE39
Últimos 12 meses27
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-5962 | Media (5.5) | 0.78% | — | 9 abr 2026 | A vulnerability was detected in Tenda CH22 1.0.0.6(468). This issue affects the function R7WebsSecurityHandlerfunction of the component httpd. The manipulation results in path traversal. The attack may be launched… |
| CVE-2026-5605 | Alta (7.4) | 0.89% | — | 6 abr 2026 | A weakness has been identified in Tenda CH22 1.0.0.1. This affects the function formWrlExtraSet of the file /goform/WrlExtraSet. Executing a manipulation of the argument GO can lead to stack-based buffer overflow. The… |
| CVE-2026-5604 | Alta (7.4) | 0.89% | — | 5 abr 2026 | A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the function formCertLocalPrecreate of the file /goform/CertLocalPrecreate of the component Parameter Handler. Performing a manipulation… |
| CVE-2026-5204 | Alta (7.4) | 1.0% | — | 31 mar 2026 | A vulnerability was determined in Tenda CH22 1.0.0.1. Affected is the function formWebTypeLibrary of the file /goform/webtypelibrary of the component Parameter Handler. This manipulation of the argument webSiteId causes… |
| CVE-2026-5156 | Alta (7.4) | 1.0% | — | 31 mar 2026 | A vulnerability was determined in Tenda CH22 1.0.0.1. This impacts the function formQuickIndex of the file /goform/QuickIndex of the component Parameter Handler. This manipulation of the argument mit_linktype causes… |
| CVE-2026-5155 | Alta (7.4) | 1.0% | — | 30 mar 2026 | A vulnerability was found in Tenda CH22 1.0.0.1. This affects the function fromAdvSetWan of the file /goform/AdvSetWan of the component Parameter Handler. The manipulation of the argument wanmode results in stack-based… |
| CVE-2026-5154 | Alta (7.4) | 1.0% | — | 30 mar 2026 | A vulnerability has been found in Tenda CH22 1.0.0.1/1.If. The impacted element is the function fromSetCfm of the file /goform/setcfm of the component Parameter Handler. The manipulation of the argument funcname leads… |
| CVE-2026-5153 | Baja (2.1) | 6.5% | — | 30 mar 2026 | A flaw has been found in Tenda CH22 1.0.0.1. The affected element is the function FormWriteFacMac of the file /goform/WriteFacMac. Executing a manipulation of the argument mac can lead to command injection. The attack… |
| CVE-2026-5152 | Alta (7.4) | 1.0% | — | 30 mar 2026 | A vulnerability was detected in Tenda CH22 1.0.0.1. Impacted is the function formCreateFileName of the file /goform/createFileName. Performing a manipulation of the argument fileNameMit results in stack-based buffer… |
| CVE-2025-15229 | Media (5.5) | 4.6% | — | 30 dic 2025 | A vulnerability has been found in Tenda CH22 up to 1.0.0.1. Affected by this vulnerability is the function fromDhcpListClient of the file /goform/DhcpListClient. Such manipulation of the argument LISTLEN leads to denial… |
| CVE-2025-15076 | Media (5.5) | 0.68% | — | 25 dic 2025 | A weakness has been identified in Tenda CH22 1.0.0.1. Impacted is an unknown function of the file /public/. Executing a manipulation can lead to path traversal. The attack can be launched remotely. The exploit has been… |
| CVE-2025-14526 | Alta (7.4) | 0.76% | — | 11 dic 2025 | A security flaw has been discovered in Tenda CH22 1.0.0.1. This affects the function frmL7ImForm of the file /goform/L7Im. Performing a manipulation of the argument page results in buffer overflow. Remote exploitation… |
| CVE-2025-13400 | Alta (7.4) | 0.69% | — | 19 nov 2025 | A vulnerability was detected in Tenda CH22 1.0.0.1. Affected is the function formWrlExtraGet of the file /goform/WrlExtraGet. Performing a manipulation of the argument chkHz results in buffer overflow. Remote… |
| CVE-2025-13288 | Alta (7.4) | 0.88% | — | 17 nov 2025 | A security vulnerability has been detected in Tenda CH22 1.0.0.1. This impacts the function fromPptpUserSetting of the file /goform/PPTPUserSetting. The manipulation of the argument delno leads to buffer overflow. The… |
| CVE-2025-12322 | Alta (7.4) | 0.79% | — | 27 oct 2025 | A flaw has been found in Tenda CH22 1.0.0.1. Affected by this issue is the function fromNatStaticSetting of the file /goform/NatStaticSetting. Executing a manipulation of the argument page can lead to buffer overflow.… |
| CVE-2025-12274 | Alta (7.4) | 0.71% | — | 27 oct 2025 | A security vulnerability has been detected in Tenda CH22 1.0.0.1. Affected by this vulnerability is the function fromP2pListFilter of the file /goform/P2pListFilter. The manipulation of the argument page leads to buffer… |
| CVE-2025-12273 | Alta (7.4) | 1.0% | — | 27 oct 2025 | A weakness has been identified in Tenda CH22 1.0.0.1. Affected is the function fromwebExcptypemanFilter of the file /goform/webExcptypemanFilter. Executing a manipulation of the argument page can lead to buffer… |
| CVE-2025-12272 | Alta (7.4) | 0.75% | — | 27 oct 2025 | A security flaw has been discovered in Tenda CH22 1.0.0.1. This impacts the function fromAddressNat of the file /goform/addressNat. Performing a manipulation of the argument page results in buffer overflow. The attack… |
| CVE-2025-12271 | Alta (7.4) | 1.0% | — | 27 oct 2025 | A vulnerability was identified in Tenda CH22 1.0.0.1. This affects the function fromRouteStatic of the file /goform/RouteStatic. Such manipulation of the argument page leads to buffer overflow. The attack can be… |
| CVE-2025-12265 | Alta (7.4) | 1.0% | — | 27 oct 2025 | A weakness has been identified in Tenda CH22 1.0.0.1. Affected by this issue is the function fromVirtualSer of the file /goform/VirtualSer. This manipulation of the argument page causes buffer overflow. Remote… |
| CVE-2025-12236 | Alta (7.4) | 3.5% | — | 27 oct 2025 | A vulnerability was determined in Tenda CH22 1.0.0.1. This issue affects the function fromDhcpListClient of the file /goform/DhcpListClient. This manipulation of the argument page causes buffer overflow. Remote… |
| CVE-2025-12235 | Alta (7.3) | 5.2% | — | 27 oct 2025 | A vulnerability was found in Tenda CH22 1.0.0.1. This vulnerability affects the function fromSetIpBind of the file /goform/SetIpBind. The manipulation of the argument page results in buffer overflow. The attack must… |
| CVE-2025-12233 | Alta (7.4) | 4.7% | — | 27 oct 2025 | A flaw has been found in Tenda CH22 1.0.0.1. Affected by this issue is the function fromSafeUrlFilter of the file /goform/SafeUrlFilter. Executing a manipulation of the argument page can lead to buffer overflow. The… |
| CVE-2025-12234 | Alta (7.4) | 1.1% | — | 27 oct 2025 | A vulnerability has been found in Tenda CH22 1.0.0.1. This affects the function fromSafeMacFilter of the file /goform/SafeMacFilter. The manipulation of the argument page leads to buffer overflow. The attack may be… |
| CVE-2025-12232 | Alta (7.4) | 4.9% | — | 27 oct 2025 | A vulnerability was detected in Tenda CH22 1.0.0.1. Affected by this vulnerability is the function fromSafeClientFilter of the file /goform/SafeClientFilter. Performing a manipulation of the argument page results in… |
| CVE-2025-11423 | Alta (8.9) | 0.86% | — | 8 oct 2025 | A vulnerability was found in Tenda CH22 1.0.0.1. This affects the function formSafeEmailFilter of the file /goform/SafeEmailFilter. Performing a manipulation of the argument page results in memory corruption. The attack… |
| CVE-2025-11418 | Alta (8.9) | 6.7% | — | 8 oct 2025 | A security vulnerability has been detected in Tenda CH22 up to 1.0.0.1. This issue affects the function formWrlsafeset of the file /goform/AdvSetWrlsafeset of the component HTTP Request Handler. The manipulation of the… |
| CVE-2025-11117 | Alta (7.4) | 0.80% | — | 28 sept 2025 | A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formWrlExtraGet of the file /goform/GstDhcpSetSer. This manipulation of the argument dips causes buffer overflow. The attack… |
| CVE-2025-9813 | Alta (7.4) | 0.87% | — | 2 sept 2025 | A vulnerability was identified in Tenda CH22 1.0.0.1. This issue affects the function formSetSambaConf of the file /goform/SetSambaConf. The manipulation of the argument samba_userNameSda leads to buffer overflow. It is… |
| CVE-2025-9812 | Alta (7.4) | 0.66% | — | 2 sept 2025 | A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formexeCommand of the file /goform/exeCommand. Executing manipulation of the argument cmdinput can lead to buffer overflow.… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.