CVE Tools

CH22 Firmware

39 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for CH22 Firmware, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.

CH22 Firmware CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
CH22 Firmware CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-062
2025-071
2025-084
2025-093
2025-1013
2025-112
2025-123
2026-010
2026-020
2026-036
2026-043
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 39 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical410%
  • High3385%
  • Medium25%

Latest CVEs

The 15 most recently published vulnerabilities affecting CH22 Firmware.

  1. CVE-2026-5962Tenda CH22 httpd R7WebsSecurityHandlerfunction path traversal7.3
  2. CVE-2026-5605Tenda CH22 WrlExtraSet formWrlExtraSet stack-based overflow8.8
  3. CVE-2026-5604Tenda CH22 Parameter CertLocalPrecreate formCertLocalPrecreate stack-based overflow8.8
  4. CVE-2026-5204Tenda CH22 Parameter webtypelibrary formWebTypeLibrary stack-based overflow8.8
  5. CVE-2026-5156Tenda CH22 Parameter QuickIndex formQuickIndex stack-based overflow8.8
  6. CVE-2026-5155Tenda CH22 Parameter AdvSetWan fromAdvSetWan stack-based overflow8.8
  7. CVE-2026-5154Tenda CH22 Parameter setcfm fromSetCfm stack-based overflow8.8
  8. CVE-2026-5153Tenda CH22 WriteFacMac FormWriteFacMac command injection6.3
  9. CVE-2026-5152Tenda CH22 createFileName formCreateFileName stack-based overflow8.8
  10. CVE-2025-15229Tenda CH22 DhcpListClient fromDhcpListClient denial of service5.3
  11. CVE-2025-15076Tenda CH22 public path traversal7.3
  12. CVE-2025-14526Tenda CH22 L7Im frmL7ImForm buffer overflow8.8
  13. CVE-2025-13400Tenda CH22 WrlExtraGet formWrlExtraGet buffer overflow8.8
  14. CVE-2025-13288Tenda CH22 PPTPUserSetting fromPptpUserSetting buffer overflow8.8
  15. CVE-2025-12322Tenda CH22 NatStaticSetting fromNatStaticSetting buffer overflow8.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store