CVE-2025-15076

A weakness has been identified in Tenda CH22 1.0.0.1. Impacted is an unknown function of the file /public/. Executing a manipulation can lead to path traversal. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tenda:ch22_firmware:1.0.0.1:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ch22:-:*:*:*:*:*:*:*

History

24 Feb 2026, 07:16

Type Values Removed Values Added
Summary (en) A weakness has been identified in Tenda CH22 1.0.0.1. Impacted is an unknown function of the file /public/. Executing manipulation can lead to path traversal. The attack can be launched remotely. The exploit has been made available to the public and could be exploited. (en) A weakness has been identified in Tenda CH22 1.0.0.1. Impacted is an unknown function of the file /public/. Executing a manipulation can lead to path traversal. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.

30 Dec 2025, 19:17

Type Values Removed Values Added
References () https://github.com/master-abc/cve/blob/main/Tenda%20CH22%20V1.0.0.1%20Router%20Authentication%20Bypass%20Vulnerability%20in%20R7WebsSecurityHandler%20function.md - () https://github.com/master-abc/cve/blob/main/Tenda%20CH22%20V1.0.0.1%20Router%20Authentication%20Bypass%20Vulnerability%20in%20R7WebsSecurityHandler%20function.md - Exploit, Third Party Advisory
References () https://vuldb.com/?ctiid.338333 - () https://vuldb.com/?ctiid.338333 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.338333 - () https://vuldb.com/?id.338333 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.721411 - () https://vuldb.com/?submit.721411 - Third Party Advisory, VDB Entry
References () https://www.tenda.com.cn/ - () https://www.tenda.com.cn/ - Product
CPE cpe:2.3:h:tenda:ch22:-:*:*:*:*:*:*:*
cpe:2.3:o:tenda:ch22_firmware:1.0.0.1:*:*:*:*:*:*:*
First Time Tenda
Tenda ch22
Tenda ch22 Firmware

25 Dec 2025, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-25 04:15

Updated : 2026-02-24 07:16


NVD link : CVE-2025-15076

Mitre link : CVE-2025-15076

CVE.ORG link : CVE-2025-15076


JSON object : View

Products Affected

tenda

  • ch22_firmware
  • ch22
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')