CVE-2025-12236

8.8

Tenda · CH22

A buffer overflow vulnerability in the Tenda CH22 router, specifically within the fromDhcpListClient function, allows for remote memory corruption via the page argument.

Executive summary

A critical buffer overflow vulnerability in Tenda CH22 routers allows remote attackers to trigger memory corruption, posing a severe risk of unauthorized system manipulation.

Vulnerability

This vulnerability involves a buffer overflow in the fromDhcpListClient function within the /goform/DhcpListClient file. The flaw is triggered by manipulating the page argument, which can be exploited by an authenticated user to achieve remote memory corruption.

Business impact

Successful exploitation of this vulnerability leads to memory corruption, which can result in a complete compromise of the device integrity, potential service disruption, or unauthorized administrative control. With a CVSS score of 8.8, this high-severity flaw represents a significant risk to network availability and security, particularly if the device is used as an edge gateway.

Remediation

Immediate Action: Since no official patch is currently available, administrators should restrict network access to the management interface and monitor the device for any signs of abnormal behavior.

Proactive Monitoring: Security teams should review logs for suspicious traffic directed at the /goform/DhcpListClient endpoint and monitor for unexpected device reboots or performance degradation.

Compensating Controls: Implement strict firewall rules to ensure that only authorized IP addresses can access the administrative management interface of the device, effectively isolating the vulnerable function from external threats.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists and is attributed to the technical documentation provided in the vulnerability research repository at https://github.com/QIU-DIE/CVE/issues/17.

Analyst recommendation

Given the existence of a public proof-of-concept and the potential for total impact on the affected device, this vulnerability must be treated with high priority. Organizations should immediately apply network-level segmentation to protect the Tenda CH22 interface and maintain a close watch on vendor communications for the release of a firmware update to resolve this memory corruption issue.

More Tenda CVEs

Sources

Originally found and disclosed by LINXI666 (VulDB User), per the CVE Program record.