Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Wakaka123

#14934of 53,638
18Total CVSS
Vulnerabilities · 2
High
2
PT-2025-35536
9.0
2025-08-25
Tenda · Tenda Ch22 · CVE-2025-9812
**Name of the Vulnerable Software and Affected Versions** Tenda CH22 version 1.0.0.1 **Description** A buffer overflow issue exists in the `formexeCommand` function of the `/goform/exeCommand` file. Manipulation of the `cmdinput` argument can lead to a buffer overflow, potentially allowing for remote exploitation. The exploit has been publicly disclosed. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2025-35537
9.0
2025-08-25
Tenda · Tenda Ch22 · CVE-2025-9813
**Name of the Vulnerable Software and Affected Versions** Tenda CH22 version 1.0.0.1 **Description** A buffer overflow issue exists in the `formSetSambaConf` function of the `/goform/SetSambaConf` file. The manipulation of the `samba userNameSda` argument can trigger this issue, allowing for remote exploitation. The exploit is publicly available. **Recommendations** Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the `/goform/SetSambaConf` file. Avoid using the `samba userNameSda` argument in the affected function until the issue is resolved.