CVE-2025-9748: Tenda CH22 httpd IPSECsave fromIpsecitem stack-based overflow
A vulnerability was determined in Tenda CH22 1.0.0.1. Affected by this issue is the function fromIpsecitem of the file /goform/IPSECsave of the component httpd. Executing manipulation of the argument ipsecno can lead to stack-based buffer overflow. The attack may be performed from remote.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9748?
CVE-2025-9748 has a high severity rating due to the potential for stack-based buffer overflow that could be exploited remotely.
How do I fix CVE-2025-9748?
To mitigate CVE-2025-9748, it is recommended to update the Tenda CH22 firmware to the latest version provided by the vendor.
What types of attacks can exploit CVE-2025-9748?
CVE-2025-9748 can be exploited through remote code execution via manipulation of the ipsecno argument.
Who is affected by CVE-2025-9748?
Users of the Tenda CH22 router running Firmware version 1.0.0.1 are affected by CVE-2025-9748.
What component of Tenda CH22 is affected by CVE-2025-9748?
CVE-2025-9748 affects the httpd component of the Tenda CH22 firmware, specifically the fromIpsecitem function.