CVE-2025-9297: Tenda i22 wxportalauth formWeixinAuthInfoGet stack-based overflow
A vulnerability was detected in Tenda i22 1.0.0.3(4687). This impacts the function formWeixinAuthInfoGet of the file /goform/wxportalauth. Performing manipulation of the argument Type results in stack-based buffer overflow. The attack can be initiated remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9297?
CVE-2025-9297 has a high severity rating due to the potential for remote exploitation leading to a stack-based buffer overflow.
How do I fix CVE-2025-9297?
To fix CVE-2025-9297, update the Tenda i22 firmware to the latest version available from the vendor.
Who is affected by CVE-2025-9297?
CVE-2025-9297 affects users of the Tenda i22 version 1.0.0.3 and below.
What type of vulnerability is CVE-2025-9297?
CVE-2025-9297 is a stack-based buffer overflow vulnerability.
Can CVE-2025-9297 be exploited remotely?
Yes, CVE-2025-9297 can be exploited remotely, allowing attackers to manipulate the argument Type.