← Terug naar overzicht

A command injection vulnerability has been identified in Tenda CH22 firmware version 1.0.0.1. The vulnerability exists in the formcreateFileName function within the /goform/formcreateFileName endpoint. Attackers can manipulate the fileNameMit argument to inject arbitrary commands. The attack can be launched remotely without requiring physical access to the device. A public exploit has already been disclosed, increasing the risk of active exploitation. This affects Tenda CH22 routers, which are network infrastructure devices. The vulnerability is classified as high severity due to its remote exploitability and public disclosure. No patch or mitigation details are mentioned in the article.

Affected products

  • Tenda CH22 1.0.0.1

Related CVE's

  • CVE-2026-77031

Categories

  • Mobile & IoT
  • Network Infrastructure