Tenda CH22
cpe:2.3:h:tenda:ch22:*:*:*:*:*:*:*, +1 more
- 1.0.0.1
A buffer overflow vulnerability has been identified in the Tenda CH22 router, specifically in version 1.0.0.1. The issue arises in the function formeditFileName within the file /goform/editFileName. This vulnerability allows for remote exploitation, where an attacker can manipulate the input to cause a buffer overflow, potentially leading to arbitrary code execution or causing the device to crash and become unresponsive.
Exploitation of this vulnerability causes a stack overflow, disrupting the normal operation of the router and making it inaccessible.
The vulnerability can be reproduced by sending a POST request to the /goform/editFileName endpoint with an oversized payload in the editNameMit parameter. This can be done using a Python script that automates the process, demonstrating the vulnerability by causing the router to crash.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.