CVE-2025-12274
8.8Tenda · CH22
A buffer overflow vulnerability in the Tenda CH22 router allows remote attackers to compromise the system via the fromP2pListFilter function.
Executive summary
A critical buffer overflow vulnerability in Tenda CH22 firmware version 1.0.0.1 exposes the device to remote code execution and full system compromise.
Vulnerability
The flaw exists in the fromP2pListFilter function within the /goform/P2pListFilter file, where improper handling of the page argument leads to a buffer overflow. This vulnerability can be triggered by an authenticated attacker to achieve remote memory corruption.
Business impact
Successful exploitation of this buffer overflow allows an attacker to gain unauthorized control over the affected Tenda network device. Given the CVSS score of 8.8, this poses a significant risk to network integrity, potentially leading to unauthorized data interception, lateral movement within the local network, or complete denial of service.
Remediation
Immediate Action: Since no official patch is currently identified, administrators should restrict access to the web management interface and disable remote management features to prevent unauthorized access.
Proactive Monitoring: Monitor network traffic for unusual patterns or large payloads directed toward the /goform/P2pListFilter endpoint, and audit system logs for signs of repeated authentication attempts or service crashes.
Compensating Controls: Implement strict firewall rules to ensure that the management interface of the Tenda CH22 is not exposed to the public internet or untrusted network segments.
Exploitation status
Public Exploit Available: Yes, a public proof of concept has been disclosed via the researcher's GitHub repository.
Analyst recommendation
The severity of this memory corruption vulnerability necessitates immediate defensive action. Organizations utilizing the Tenda CH22 should isolate the device from external networks until a vendor firmware update is released and applied, as the existence of a public proof of concept increases the likelihood of opportunistic exploitation.
More Tenda CVEs
Sources
Originally found and disclosed by hhsw34 (VulDB User), per the CVE Program record.
- VDB-329946 | Tenda CH22 P2pListFilter fromP2pListFilter buffer overflow Vulnerability database entry
- VDB-329946 | CTI Indicators (IOB, IOC, IOA)
- Submit #674165 | Tenda CH22 V1.0.0.1 Buffer Overflow Third-party advisory
- Exploit / PoC
- tenda.com.cn