CVE-2025-8180: Tenda CH22 deleteUserName formdeleteUserName buffer overflow
Published Jul 26, 2025
·Updated
A vulnerability, which was classified as critical, has been found in Tenda CH22 1.0.0.1. Affected by this issue is the function formdeleteUserName of the file /goform/deleteUserName. The manipulation of the argument oldaccount leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
3 affected components
Tenda CH22
All of the following
Tenda Ch22 Firmware=1.0.0.1
Tenda CH22
Event History
Jul 26, 2025
CVE Published
via MITRE·06:32 AM
Data Sourced
via MITRE·06:32 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeaknessAffected Software
Jun 22, 58473
Event
via NVD·05:44 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-8180?
CVE-2025-8180 is classified as a critical vulnerability.
2
How do I fix CVE-2025-8180?
To fix CVE-2025-8180, update the Tenda CH22 firmware to the latest version.
3
What type of vulnerability is CVE-2025-8180?
CVE-2025-8180 is a buffer overflow vulnerability affecting the function formdeleteUserName.
4
Which device is affected by CVE-2025-8180?
CVE-2025-8180 affects the Tenda CH22 device.
5
What impacts could CVE-2025-8180 have on my system?
Exploitation of CVE-2025-8180 could lead to remote code execution due to the buffer overflow.