CVE-2025-9813: Tenda CH22 SetSambaConf formSetSambaConf buffer overflow
A vulnerability was identified in Tenda CH22 1.0.0.1. This issue affects the function formSetSambaConf of the file /goform/SetSambaConf. The manipulation of the argument sambauserNameSda leads to buffer overflow. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9813?
The severity of CVE-2025-9813 is considered high due to the potential for remote code execution through buffer overflow.
How does CVE-2025-9813 affect Tenda CH22 devices?
CVE-2025-9813 affects Tenda CH22 devices by allowing remote attackers to exploit a buffer overflow in the samba configuration.
What are the possible impacts of exploiting CVE-2025-9813?
Exploiting CVE-2025-9813 could lead to unauthorized access, execution of arbitrary code, or full control over the affected Tenda CH22 device.
How do I fix CVE-2025-9813?
To fix CVE-2025-9813, users should update their Tenda CH22 firmware to the latest version recommended by Tenda.
Is there a way to mitigate CVE-2025-9813 if I cannot update?
To mitigate CVE-2025-9813, it is advisable to disable samba services on Tenda CH22 devices until a patch is available.