---
id: CVE-2025-12273
title: A weakness has been identified in Tenda CH22 1.0.0.1
summary: >-
  A weakness has been identified in Tenda CH22 1.0.0.1. Affected is the function
  fromwebExcptypemanFilter of the file /goform/webExcptypemanFilter. Executing a
  manipulation of the argument page can lead to buffer overflow. The attack may
  b…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-119
  - CWE-120
vendor: tenda
product: ch22_firmware
affected:
  - ch22_firmware = 1.0.0.1
published: '2025-10-27'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T11:10:00.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-12273'
references:
  - url: 'https://github.com/QIU-DIE/CVE/issues/22'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.329945'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.329945'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.674161'
    label: cna@vuldb.com
  - url: 'https://www.tenda.com.cn/'
    label: cna@vuldb.com
  - url: 'https://github.com/QIU-DIE/CVE/issues/22'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.01006
epssPercentile: 0.61874
ingestedAt: '2026-10-08T11:31:27.632Z'
---

## Overview

A weakness has been identified in Tenda CH22 1.0.0.1. Affected is the function fromwebExcptypemanFilter of the file /goform/webExcptypemanFilter. Executing a manipulation of the argument page can lead to buffer overflow. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.

## Affected

- `ch22_firmware = 1.0.0.1`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
