CVE-2025-12322: Tenda CH22 NatStaticSetting fromNatStaticSetting buffer overflow
A flaw has been found in Tenda CH22 1.0.0.1. Affected by this issue is the function fromNatStaticSetting of the file /goform/NatStaticSetting. Executing a manipulation of the argument page can lead to buffer overflow. It is possible to launch the attack remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12322?
CVE-2025-12322 is considered a high severity vulnerability due to the potential for remote exploitation leading to buffer overflow.
How do I fix CVE-2025-12322?
To fix CVE-2025-12322, update the Tenda CH22 firmware to the latest version provided by the vendor.
What is the attack vector for CVE-2025-12322?
CVE-2025-12322 can be exploited remotely through manipulation of the argument in the function fromNatStaticSetting.
What systems are affected by CVE-2025-12322?
CVE-2025-12322 affects the Tenda CH22 router running version 1.0.0.1.
Can CVE-2025-12322 be exploited without authentication?
Yes, CVE-2025-12322 can be exploited without authentication, allowing unauthenticated attackers to launch the exploit.