Tenda CH22 Buffer Overflow Vulnerability in SafeEmailFilter Endpoint

Vulnerability

A critical buffer overflow vulnerability has been identified in the Tenda CH22 router, version 1.0.0.1. The issue arises in the SafeEmailFilter endpoint, specifically within the formSafeEmailFilter function. The vulnerability allows for memory corruption by manipulating the user-controlled page parameter. This flaw can be exploited remotely, without any authentication requirements, leading to potential application crashes, arbitrary code execution, and disruption of normal device operations.

Impact

Exploitation of this vulnerability can cause memory corruption, application crashes, and arbitrary code execution. If code execution is achieved, it could allow an attacker to escalate privileges, implant backdoors, manipulate email filtering settings, or disrupt the device's firmware, rendering it unusable. Even without executing code, the vulnerability could compromise sensitive data and cause significant operational disruptions.

Reproduction

The vulnerability can be reproduced by sending a POST request to the SafeEmailFilter endpoint with an oversized payload in the page parameter. This can be done using a script that automates the request, such as one written in Python using the requests library.

Added: Oct 8, 2025, 2:20 AM
Updated: Oct 8, 2025, 2:20 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
6.0
remediation
0.0
relevance
0.7
threat
6.4
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.