CVE-2025-12234

8.8

Tenda · CH22

A buffer overflow vulnerability in the Tenda CH22 router's SafeMacFilter function allows remote authenticated attackers to trigger memory corruption via the page argument.

Executive summary

A critical buffer overflow vulnerability in Tenda CH22 firmware version 1.0.0.1 exposes devices to remote memory corruption and potential system compromise.

Vulnerability

The flaw exists within the fromSafeMacFilter function located in the /goform/SafeMacFilter file. By sending a specially crafted request to the page argument, a remote authenticated attacker can trigger a buffer overflow, leading to memory corruption.

Business impact

Successful exploitation of this vulnerability can result in a complete loss of device integrity and potential service disruption. Given the CVSS score of 8.8, this poses a high risk to network infrastructure stability and could facilitate unauthorized access to the underlying hardware, potentially compromising the local network managed by the affected Tenda device.

Remediation

Immediate Action: Since no official patch is currently confirmed, administrators should restrict access to the web management interface of the Tenda CH22 to trusted internal management subnets only.

Proactive Monitoring: Monitor system logs for unusual crash events, unexpected reboots, or unauthorized access attempts targeting the /goform/SafeMacFilter endpoint.

Compensating Controls: Implement network segmentation to isolate the management interface from public exposure and use firewall rules to limit access to the device's administration portal.

Exploitation status

Public Exploit Available: Yes, a public proof of concept exists, as evidenced by the technical documentation provided in the referenced GitHub repository.

Analyst recommendation

Given the availability of a public proof of concept and the high severity of memory corruption vulnerabilities, Tenda CH22 devices are at significant risk. Organizations should immediately restrict external access to the device management interface and maintain a posture of heightened vigilance until an official firmware update addressing this buffer overflow is released by the vendor.

More Tenda CVEs

Sources

Originally found and disclosed by LINXI666 (VulDB User), per the CVE Program record.