CVE-2025-9812: Tenda CH22 exeCommand formexeCommand buffer overflow
A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formexeCommand of the file /goform/exeCommand. Executing manipulation of the argument cmdinput can lead to buffer overflow. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9812?
CVE-2025-9812 is considered critical due to its potential for remote exploitation and the resulting buffer overflow.
How do I fix CVE-2025-9812?
To fix CVE-2025-9812, update the Tenda CH22 firmware to the latest version that addresses this vulnerability.
What are the potential impacts of CVE-2025-9812?
CVE-2025-9812 can allow an attacker to execute arbitrary code remotely, leading to unauthorized access and potential system compromise.
Who is affected by CVE-2025-9812?
CVE-2025-9812 affects users of the Tenda CH22 router running firmware version 1.0.0.1.
Is there a way to mitigate the risks of CVE-2025-9812?
Yes, limiting remote access to the Tenda CH22, using strong passwords, and regularly updating firmware can help mitigate the risks associated with CVE-2025-9812.