Tenda · Tenda Ch22 · CVE-2025-8180
**Name of the Vulnerable Software and Affected Versions**
Tenda CH22 version 1.0.0.1
**Description**
A critical issue exists in the `formdeleteUserName` function within the `/goform/deleteUserName` file. The `old account` argument is susceptible to buffer overflow, allowing for remote exploitation. The exploit for this issue has been publicly disclosed.
**Recommendations**
Tenda CH22 version 1.0.0.1: As a temporary workaround, consider restricting access to the `/goform/deleteUserName` file to minimize the risk of exploitation.