CVE-2025-11423 PUBLISHED

Tenda CH22 SafeEmailFilter formSafeEmailFilter memory corruption

Assigner: VulDB
Reserved: 07.10.2025 Published: 08.10.2025 Updated: 08.10.2025

A vulnerability was found in Tenda CH22 1.0.0.1. This affects the function formSafeEmailFilter of the file /goform/SafeEmailFilter. Performing manipulation of the argument page results in memory corruption. The attack is possible to be carried out remotely. The exploit has been made public and could be used.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
CVSS Score: 9.3

Product Status

Vendor Tenda
Product CH22
Versions
  • Version 1.0.0.1 is affected

Credits

  • Li Hu (VulDB User) reporter

References

Problem Types

  • Memory Corruption CWE