Vulnerability Description
A security flaw has been discovered in Tenda CH22 1.0.0.1. This affects the function frmL7ImForm of the file /goform/L7Im. Performing a manipulation of the argument page results in buffer overflow. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tenda | Ch22 Firmware | 1.0.0.1 |
| Tenda | Ch22 | - |
Related Weaknesses (CWE)
References
- https://github.com/maximdevere/CVE2/issues/5ExploitIssue TrackingThird Party Advisory
- https://github.com/maximdevere/CVE2/issues/5#issue-3673676260ExploitIssue TrackingThird Party Advisory
- https://vuldb.com/?ctiid.335866Permissions RequiredVDB Entry
- https://vuldb.com/?id.335866Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.703035Third Party AdvisoryVDB Entry
- https://www.tenda.com.cn/Product
FAQ
What is CVE-2025-14526?
CVE-2025-14526 is a vulnerability with a CVSS score of 8.8 (HIGH). A security flaw has been discovered in Tenda CH22 1.0.0.1. This affects the function frmL7ImForm of the file /goform/L7Im. Performing a manipulation of the argument page results in buffer overflow. Re...
How severe is CVE-2025-14526?
CVE-2025-14526 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-14526?
Check the references section above for vendor advisories and patch information. Affected products include: Tenda Ch22 Firmware, Tenda Ch22.