CVE-2025-5619: Tenda CH22 addUserName formaddUserName stack-based overflow
Published Jun 4, 2025
·Updated
A vulnerability, which was classified as critical, has been found in Tenda CH22 1.0.0.1. This issue affects the function formaddUserName of the file /goform/addUserName. The manipulation of the argument Password leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
3 affected components
Tenda CH22
All of the following
Tenda Ch22 Firmware=1.0.0.1
Tenda CH22
Event History
Jun 4, 2025
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
DescriptionSeverityWeakness
Jan 12, 57458
Event
via FIRST·06:29 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-5619?
CVE-2025-5619 is classified as a critical vulnerability.
2
What type of vulnerability is CVE-2025-5619?
CVE-2025-5619 is a stack-based buffer overflow vulnerability.
3
What component is affected by CVE-2025-5619?
CVE-2025-5619 affects the function formaddUserName in the Tenda CH22 firmware.
4
How can an attacker exploit CVE-2025-5619?
An attacker can exploit CVE-2025-5619 remotely by manipulating the Password argument.
5
How do I fix CVE-2025-5619?
To fix CVE-2025-5619, update the Tenda CH22 firmware to the latest version.