CVE-2025-9006: Tenda CH22 delFileName formdelFileName buffer overflow
A vulnerability was identified in Tenda CH22 1.0.0.1. Affected by this vulnerability is the function formdelFileName of the file /goform/delFileName. The manipulation leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9006?
The severity of CVE-2025-9006 is high due to its potential for remote exploitation and the presence of a buffer overflow.
How do I fix CVE-2025-9006?
To fix CVE-2025-9006, update the Tenda CH22 firmware to the latest version provided by the vendor.
What impact does CVE-2025-9006 have on Tenda CH22 devices?
CVE-2025-9006 can lead to potential unauthorized access and remote code execution due to buffer overflow.
Is CVE-2025-9006 publicly known?
Yes, CVE-2025-9006 has been disclosed publicly, increasing the risk of exploitation.
Can CVE-2025-9006 be exploited without local access?
Yes, CVE-2025-9006 can be exploited remotely, allowing attackers to execute code without local access.