CVE-2025-12235: Tenda CH22 SetIpBind fromSetIpBind buffer overflow
A vulnerability was found in Tenda CH22 1.0.0.1. This vulnerability affects the function fromSetIpBind of the file /goform/SetIpBind. The manipulation of the argument page results in buffer overflow. The attack must originate from the local network. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12235?
The severity of CVE-2025-12235 is considered critical due to the potential for a buffer overflow that can be exploited locally.
How do I fix CVE-2025-12235?
To fix CVE-2025-12235, it is recommended to update the Tenda CH22 firmware to the latest version provided by the manufacturer.
What type of attack is associated with CVE-2025-12235?
CVE-2025-12235 is associated with local network attacks that exploit a buffer overflow vulnerability.
What is the impact of exploiting CVE-2025-12235?
Exploiting CVE-2025-12235 may allow an attacker to execute arbitrary code on the affected Tenda CH22 device.
Is CVE-2025-12235 remote or local access?
CVE-2025-12235 requires local network access to exploit the vulnerability.