CVE-2025-11418: Tenda CH22 HTTP Request AdvSetWrlsafeset formWrlsafeset stack-based overflow
A security vulnerability has been detected in Tenda CH22 up to 1.0.0.1. This issue affects the function formWrlsafeset of the file /goform/AdvSetWrlsafeset of the component HTTP Request Handler. The manipulation of the argument mitssidindex leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11418?
CVE-2025-11418 has a high severity rating due to its stack-based buffer overflow vulnerability.
How do I fix CVE-2025-11418?
To fix CVE-2025-11418, update your Tenda CH22 firmware to the latest version that addresses this vulnerability.
What effect does CVE-2025-11418 have on Tenda CH22?
CVE-2025-11418 can lead to unauthorized access and potential remote code execution due to the buffer overflow.
Is CVE-2025-11418 remotely exploitable?
Yes, CVE-2025-11418 can be exploited remotely through crafted HTTP requests.
What versions of Tenda CH22 are affected by CVE-2025-11418?
CVE-2025-11418 affects Tenda CH22 versions up to and including 1.0.0.1.