CVE-2025-12265

8.8

Tenda · CH22

A buffer overflow vulnerability in the Tenda CH22 router allows remote attackers to trigger memory corruption via the page argument in the fromVirtualSer function.

Executive summary

A critical buffer overflow vulnerability in Tenda CH22 firmware enables remote attackers to achieve unauthorized system control.

Vulnerability

This flaw involves a buffer overflow within the fromVirtualSer function located in the /goform/VirtualSer file. The vulnerability is triggered by manipulating the page argument, allowing for remote exploitation by an authenticated user.

Business impact

The exploitation of this vulnerability could lead to a complete compromise of the affected network device, resulting in unauthorized access to internal network traffic or service disruption. Given the CVSS score of 8.8, this represents a high severity risk that could facilitate lateral movement within the network or the establishment of persistent backdoors. Organizations relying on this hardware face significant security exposure if the device is accessible from untrusted networks.

Remediation

Immediate Action: Contact Tenda support or check the official vendor website for firmware updates addressing this buffer overflow, as no specific patch version is currently identified.

Proactive Monitoring: Monitor network traffic for anomalous requests directed at the /goform/VirtualSer endpoint and inspect system logs for signs of unauthorized configuration changes.

Compensating Controls: Implement strict access control lists on the management interface of the Tenda CH22 to restrict access to known, trusted administrative IP addresses.

Exploitation status

Public Exploit Available: Yes, a public proof of concept is available via the GitHub issue referenced in the vulnerability disclosure.

Analyst recommendation

The severity of this memory corruption vulnerability necessitates immediate attention to prevent potential remote code execution. Administrators should prioritize restricting network access to the affected devices and seek official firmware updates from Tenda to permanently remediate the underlying flaw.

More Tenda CVEs

Sources

Originally found and disclosed by hhsw34 (VulDB User), per the CVE Program record.