CVE-2025-15229
⚪ Do wiadomości
Błąd w Tenda CH22 umożliwia zdalne wywołanie odmowy usługi przez manipulację argumentem LISTLEN.
CVSS
5.3
EPSS
4.6%
Exploit
poc
Vendor
tenda
Opis źródłowy (NVD)
A vulnerability has been found in Tenda CH22 up to 1.0.0.1. Affected by this vulnerability is the function fromDhcpListClient of the file /goform/DhcpListClient. Such manipulation of the argument LISTLEN leads to denial of service. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
dos exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 5.3 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 4.6% |
| Opublikowano (NVD) | 2025-12-30 06:15:41 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-05 17:10:00 UTC |
Referencje
- https://github.com/master-abc/cve/issues/7 ([email protected]) [Exploit, Issue Tracking, Third Party Advisory]
- https://vuldb.com/?ctiid.338625 ([email protected]) [Permissions Required, VDB Entry]
- https://vuldb.com/?id.338625 ([email protected]) [Third Party Advisory, VDB Entry]
- https://vuldb.com/?submit.725472 ([email protected]) [Third Party Advisory, VDB Entry]
- https://www.tenda.com.cn/ ([email protected]) [Product]