CVE-2025-13288: Tenda CH22 PPTPUserSetting fromPptpUserSetting buffer overflow
A security vulnerability has been detected in Tenda CH22 1.0.0.1. This impacts the function fromPptpUserSetting of the file /goform/PPTPUserSetting. The manipulation of the argument delno leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13288?
CVE-2025-13288 has a high severity rating due to its potential for remote exploitation and buffer overflow risks.
How do I fix CVE-2025-13288?
To mitigate CVE-2025-13288, it is recommended to update the Tenda CH22 firmware to the latest version that addresses this vulnerability.
What type of vulnerability is CVE-2025-13288?
CVE-2025-13288 is classified as a buffer overflow vulnerability that can be exploited remotely.
Which devices are affected by CVE-2025-13288?
CVE-2025-13288 specifically affects the Tenda CH22 router running version 1.0.0.1.
What can attackers achieve with CVE-2025-13288?
Exploiting CVE-2025-13288 allows attackers to execute arbitrary code on the affected device remotely.