← Back to overview

A command injection vulnerability has been identified in Tenda CH22 firmware version 1.0.0.1. The flaw exists in the formexeCommand function within the /goform/exeCommand file. An attacker can exploit this vulnerability by manipulating the cmdinput argument to inject arbitrary commands. The attack can be initiated remotely without physical access to the device. A public exploit has already been disclosed, increasing the risk of active exploitation. This type of vulnerability is particularly concerning for IoT and network devices as they are often exposed to the internet. The vulnerability has been assigned CVE-2026-78141 and is tracked in VulDB as well as NVD.

Affected products

  • Tenda CH22 1.0.0.1

Related CVE's

  • CVE-2026-78141

Categories

  • Mobile & IoT
  • Network Infrastructure
  • Zero-Day Vulnerabilities