CVE-2025-15229

A vulnerability has been found in Tenda CH22 up to 1.0.0.1. Affected by this vulnerability is the function fromDhcpListClient of the file /goform/DhcpListClient. Such manipulation of the argument LISTLEN leads to denial of service. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
References
Link Resource
https://github.com/master-abc/cve/issues/7 Exploit Issue Tracking Third Party Advisory
https://vuldb.com/?ctiid.338625 Permissions Required VDB Entry
https://vuldb.com/?id.338625 Third Party Advisory VDB Entry
https://vuldb.com/?submit.725472 Third Party Advisory VDB Entry
https://www.tenda.com.cn/ Product
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tenda:ch22_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ch22:-:*:*:*:*:*:*:*

History

07 Jan 2026, 17:43

Type Values Removed Values Added
First Time Tenda
Tenda ch22
Tenda ch22 Firmware
CPE cpe:2.3:o:tenda:ch22_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ch22:-:*:*:*:*:*:*:*
References () https://github.com/master-abc/cve/issues/7 - () https://github.com/master-abc/cve/issues/7 - Exploit, Issue Tracking, Third Party Advisory
References () https://vuldb.com/?ctiid.338625 - () https://vuldb.com/?ctiid.338625 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.338625 - () https://vuldb.com/?id.338625 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.725472 - () https://vuldb.com/?submit.725472 - Third Party Advisory, VDB Entry
References () https://www.tenda.com.cn/ - () https://www.tenda.com.cn/ - Product

30 Dec 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-30 06:15

Updated : 2026-01-07 17:43


NVD link : CVE-2025-15229

Mitre link : CVE-2025-15229

CVE.ORG link : CVE-2025-15229


JSON object : View

Products Affected

tenda

  • ch22_firmware
  • ch22
CWE
CWE-404

Improper Resource Shutdown or Release