CVE-2025-12271

8.8

Tenda · CH22

A buffer overflow vulnerability in the Tenda CH22 router allows remote attackers to execute arbitrary code via the page argument in the /goform/RouteStatic endpoint.

Executive summary

A remote buffer overflow vulnerability in Tenda CH22 firmware version 1.0.0.1 poses a high risk of total system compromise.

Vulnerability

This is a memory corruption vulnerability caused by a buffer overflow in the fromRouteStatic function within the /goform/RouteStatic file. The vulnerability is remotely exploitable by an authenticated user with low-level privileges.

Business impact

Successful exploitation of this buffer overflow allows for arbitrary code execution on the affected network device. Given the CVSS score of 8.8, this vulnerability represents a severe threat that could lead to unauthorized access to the local network, traffic interception, or the complete takeover of the device, resulting in significant operational downtime and potential data exfiltration.

Remediation

Immediate Action: Since no official patch is currently available, administrators should restrict network access to the management interface of the Tenda CH22 device to trusted internal segments only.

Proactive Monitoring: Review device access logs for unusual requests directed at the /goform/RouteStatic endpoint and monitor for unexpected service restarts which may indicate crash attempts.

Compensating Controls: Implement firewall rules to block unsolicited inbound traffic to the device management port and deploy an Intrusion Detection System (IDS) to identify patterns indicative of buffer overflow attempts.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists as documented in the technical write-up provided by the vulnerability reporter on GitHub.

Analyst recommendation

The severity of this flaw, combined with the availability of a public proof-of-concept, necessitates immediate attention. Organizations utilizing Tenda CH22 devices must prioritize network-level isolation of these units until the vendor releases a firmware update that addresses the overflow in the fromRouteStatic function.

More Tenda CVEs

Sources

Originally found and disclosed by hhsw34 (VulDB User), per the CVE Program record.