CVE-2025-11117: Tenda CH22 GstDhcpSetSer formWrlExtraGet buffer overflow
A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formWrlExtraGet of the file /goform/GstDhcpSetSer. This manipulation of the argument dips causes buffer overflow. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11117?
CVE-2025-11117 is classified as a high-severity vulnerability due to its potential for remote exploitation and buffer overflow risks.
How do I fix CVE-2025-11117?
To mitigate CVE-2025-11117, users should update their Tenda CH22 firmware to the latest version available from the vendor.
What are the risks associated with CVE-2025-11117?
The risks associated with CVE-2025-11117 include potential remote code execution and unauthorized access to sensitive information.
Who is affected by CVE-2025-11117?
CVE-2025-11117 affects users of the Tenda CH22 device firmware version 1.0.0.1.
Can CVE-2025-11117 be exploited remotely?
Yes, CVE-2025-11117 can be exploited remotely, allowing attackers to manipulate vulnerable arguments to trigger a buffer overflow.