Impact
A buffer overflow flaw exists in the formCertListInfo function of Tenda CH22 firmware 1.0.0.1. The vulnerability is triggered by manipulating the Name field supplied through the /goform/CertListInfo web endpoint. Based on the description, it is inferred that a successful overflow may permit an attacker to execute arbitrary code on the device, although the CVE text does not explicitly confirm this outcome.
Affected Systems
Tenda CH22 routers running firmware version 1.0.0.1 are affected. The vulnerability is tied to the API handling of certificate list information on the device’s web interface.
Risk and Exploitability
The high CVSS score of 8.7 indicates a significant potential impact. The EPSS value of less than 1% suggests that exploitation is presently uncommon, yet a publicly available exploit document suggests the issue can be triggered remotely via the device’s web interface. The vulnerability is not listed in the CISA KEV catalog, but the existence of a public exploit underscores the need for prompt action. The likely attack vector is a remote web request to the vulnerable endpoint from an external source.
OpenCVE Enrichment