CVE-2025-12236
8.8Tenda · CH22
A buffer overflow vulnerability in the Tenda CH22 router, specifically within the fromDhcpListClient function, allows for remote memory corruption via the page argument.
Executive summary
A critical buffer overflow vulnerability in Tenda CH22 routers allows remote attackers to trigger memory corruption, posing a severe risk of unauthorized system manipulation.
Vulnerability
This vulnerability involves a buffer overflow in the fromDhcpListClient function within the /goform/DhcpListClient file. The flaw is triggered by manipulating the page argument, which can be exploited by an authenticated user to achieve remote memory corruption.
Business impact
Successful exploitation of this vulnerability leads to memory corruption, which can result in a complete compromise of the device integrity, potential service disruption, or unauthorized administrative control. With a CVSS score of 8.8, this high-severity flaw represents a significant risk to network availability and security, particularly if the device is used as an edge gateway.
Remediation
Immediate Action: Since no official patch is currently available, administrators should restrict network access to the management interface and monitor the device for any signs of abnormal behavior.
Proactive Monitoring: Security teams should review logs for suspicious traffic directed at the /goform/DhcpListClient endpoint and monitor for unexpected device reboots or performance degradation.
Compensating Controls: Implement strict firewall rules to ensure that only authorized IP addresses can access the administrative management interface of the device, effectively isolating the vulnerable function from external threats.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists and is attributed to the technical documentation provided in the vulnerability research repository at https://github.com/QIU-DIE/CVE/issues/17.
Analyst recommendation
Given the existence of a public proof-of-concept and the potential for total impact on the affected device, this vulnerability must be treated with high priority. Organizations should immediately apply network-level segmentation to protect the Tenda CH22 interface and maintain a close watch on vendor communications for the release of a firmware update to resolve this memory corruption issue.
More Tenda CVEs
Sources
Originally found and disclosed by LINXI666 (VulDB User), per the CVE Program record.
- VDB-329906 | Tenda CH22 DhcpListClient fromDhcpListClient buffer overflow Vulnerability database entry
- VDB-329906 | CTI Indicators (IOB, IOC, IOA)
- Submit #673724 | Tenda CH22 v1.0.0.1 Buffer Overflow Third-party advisory
- Submit #721455 | Tenda CH22 V1.0.0.1 Denial of Service (Duplicate) Third-party advisory
- Exploit / PoC
- tenda.com.cn