CVE-2025-12272

8.8

Tenda · CH22

A buffer overflow vulnerability in the Tenda CH22 router allows remote attackers to trigger memory corruption via the page argument in the /goform/addressNat endpoint.

Executive summary

A critical buffer overflow vulnerability in Tenda CH22 firmware version 1.0.0.1 allows for remote code execution and system compromise.

Vulnerability

This vulnerability is a buffer overflow (CWE-120) triggered via the fromAddressNat function in the /goform/addressNat file. An authenticated attacker can send a specially crafted page argument to the endpoint to induce memory corruption.

Business impact

The exploitation of this vulnerability leads to potential remote code execution on affected networking hardware. Given the CVSS score of 8.8, this flaw presents a high risk for unauthorized network access, potential lateral movement, and total loss of device integrity. Compromise of networking equipment often provides attackers with a persistent foothold in the internal environment, posing a significant risk to organizational data confidentiality and operational continuity.

Remediation

Immediate Action: Since a specific patch version is currently unknown, administrators should restrict network access to the management interface of the Tenda CH22 to trusted IP addresses only.

Proactive Monitoring: Monitor system logs for unusual traffic patterns targeting the /goform/addressNat URI and watch for unexpected device reboots or process crashes which may indicate exploitation attempts.

Compensating Controls: Implement network segmentation to isolate the affected hardware from critical internal segments and ensure that the administrative interface is not exposed to the public internet.

Exploitation status

Public Exploit Available: Yes, a public proof of concept has been published via the researcher's GitHub repository.

Analyst recommendation

This vulnerability represents a significant security risk due to the potential for remote code execution on core networking infrastructure. Organizations utilizing the Tenda CH22 should treat this as a high priority item. Monitor the vendor website for firmware updates and apply them as soon as they become available to remediate the underlying memory corruption flaw.

More Tenda CVEs

Sources

Originally found and disclosed by hhsw34 (VulDB User), per the CVE Program record.