VulnerabilityModified
CVE-2025-12273
A weakness has been identified in Tenda CH22 1.0.0.1.
HIGH 7.4EPSS 0.93%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.93%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A weakness has been identified in Tenda CH22 1.0.0.1. Affected is the function fromwebExcptypemanFilter of the file /goform/webExcptypemanFilter. Executing a manipulation of the argument page can lead to buffer overflow. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.
- CVSS 4.0
- 7.4 HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.93% probability · 59th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119, CWE-120
- Affected
- tenda/ch22 firmware
- Source
- cna@vuldb.com
References
- https://github.com/QIU-DIE/CVE/issues/22Exploit, Issue Tracking, Third Party Advisory
- https://vuldb.com/?ctiid.329945Permissions Required, VDB Entry
- https://vuldb.com/?id.329945Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.674161Third Party Advisory, VDB Entry
- https://www.tenda.com.cn/Product
- https://github.com/QIU-DIE/CVE/issues/22Exploit, Issue Tracking, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.