Buffer Overflow Vulnerability in Tenda CH22 by Tenda
CVE-2025-12273
Key Information:
Badges
What is CVE-2025-12273?
A vulnerability exists in the Tenda CH22 router due to improper handling of user input in the fromwebExcptypemanFilter function located in /goform/webExcptypemanFilter. This weakness can be exploited through crafted requests, leading to a buffer overflow condition. An attacker can execute this manipulation remotely, potentially gaining unauthorized access or control over the device. The exploit is publicly known, and users should apply necessary mitigations.
Affected Version(s)
CH22 1.0.0.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved