CVE-2025-13288: Tenda CH22 Firmware

High severity, CVSS 8.8. EPSS: 0.9% chance of exploitation in the next 30 days.

A security vulnerability has been detected in Tenda CH22 1.0.0.1. This impacts the function fromPptpUserSetting of the file /goform/PPTPUserSetting. The manipulation of the argument delno leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.

Affected products

  • Tenda CH22 Firmware: version 1.0.0.1 only

Published 2025-11-17. Last modified 2026-06-17.