A vulnerability was found in Tenda CH22 up to 1.0.0.1. It has been classified as critical. This issue affects the function
formWrlsafeset
of the file /goform/AdvSetWrlsafeset of the component HTTP Request Handler. The manipulation of the argument mit_ssid_index leads to stack-based buffer overflow.
This vulnerability is listed as CVE-2025-11418. The attack may be initiated remotely. In addition, an exploit is available.