CVE-2025-15076: Tenda CH22 public path traversal
A weakness has been identified in Tenda CH22 1.0.0.1. Impacted is an unknown function of the file /public/. Executing a manipulation can lead to path traversal. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15076?
CVE-2025-15076 is considered a high severity vulnerability due to its potential for remote exploitation.
How do I fix CVE-2025-15076?
To mitigate CVE-2025-15076, update Tenda CH22 to the latest firmware version that addresses this vulnerability.
What type of vulnerability is CVE-2025-15076?
CVE-2025-15076 is a path traversal vulnerability that allows attackers to manipulate file paths on the affected device.
Can CVE-2025-15076 be exploited remotely?
Yes, CVE-2025-15076 can be exploited remotely by an attacker without physical access to the device.
Which product is affected by CVE-2025-15076?
CVE-2025-15076 affects the Tenda CH22 device running version 1.0.0.1.