Tenda · Tenda Ch22 · CVE-2025-11117
**Name of the Vulnerable Software and Affected Versions**
Tenda CH22 version 1.0.0.1
**Description**
A buffer overflow issue exists in the `formWrlExtraGet` function of the `/goform/GstDhcpSetSer` file. Manipulation of the `dips` argument can trigger this issue, allowing for remote exploitation. A public exploit has been disclosed.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.