Path Traversal Vulnerability in Tenda CH22 Router Firmware
CVE-2025-15076
Key Information:
Badges
What is CVE-2025-15076?
A path traversal issue has been found in the Tenda CH22 router firmware version 1.0.0.1. An unidentified function within the /public/ directory can be exploited to gain unauthorized access to files on the server. This vulnerability allows remote attackers to manipulate input data, potentially leading to the exposure of sensitive information or files. The exploit method is publicly available, raising significant concerns regarding the security posture of devices running this firmware.
Affected Version(s)
CH22 1.0.0.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved