CVE-2025-12236: Tenda CH22 DhcpListClient fromDhcpListClient buffer overflow
A vulnerability was determined in Tenda CH22 1.0.0.1. This issue affects the function fromDhcpListClient of the file /goform/DhcpListClient. This manipulation of the argument page causes buffer overflow. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12236?
The severity of CVE-2025-12236 is classified as critical due to the potential for remote code execution via buffer overflow.
How do I fix CVE-2025-12236?
To fix CVE-2025-12236, update to the latest firmware version provided by Tenda for the CH22 router.
Which devices are affected by CVE-2025-12236?
CVE-2025-12236 specifically affects the Tenda CH22 router running version 1.0.0.1.
What type of vulnerability is CVE-2025-12236?
CVE-2025-12236 is a buffer overflow vulnerability that can be exploited remotely.
Can CVE-2025-12236 be exploited remotely?
Yes, CVE-2025-12236 can be exploited remotely, allowing an attacker to execute arbitrary code.