Vulnerability Description
A vulnerability was found in Tenda CH22 1.0.0.1. This affects the function formSafeEmailFilter of the file /goform/SafeEmailFilter. Performing a manipulation of the argument page results in memory corruption. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tenda | Ch22 Firmware | 1.0.0.1 |
| Tenda | Ch22 | - |
Related Weaknesses (CWE)
References
- https://github.com/f000x0/cve/issues/7ExploitIssue TrackingThird Party Advisory
- https://vuldb.com/?ctiid.327358Permissions RequiredVDB Entry
- https://vuldb.com/?id.327358Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.666009Third Party AdvisoryVDB Entry
- https://www.tenda.com.cn/Product
FAQ
What is CVE-2025-11423?
CVE-2025-11423 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A vulnerability was found in Tenda CH22 1.0.0.1. This affects the function formSafeEmailFilter of the file /goform/SafeEmailFilter. Performing a manipulation of the argument page results in memory cor...
How severe is CVE-2025-11423?
CVE-2025-11423 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-11423?
Check the references section above for vendor advisories and patch information. Affected products include: Tenda Ch22 Firmware, Tenda Ch22.