PT-2025-53848 · Tenda · Tenda Ch22

·

CVE-2025-15229

·

Published

2025-12-22

·

Updated

2025-12-30

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Tenda CH22 versions up to 1.0.0.1
Description A flaw exists in Tenda CH22 that allows for a denial of service. This issue stems from manipulating the LISTLEN argument within the fromDhcpListClient function located in the /goform/DhcpListClient file. The attack can be initiated remotely. The exploit for this issue has been publicly disclosed.
Recommendations Versions up to 1.0.0.1 should be updated to a newer, secure version when available.

Exploit

Fix

DoS

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-00307
CVE-2025-15229

Affected Products

Tenda Ch22