A critical security vulnerability has been identified in Tenda CH22 firmware version 1.0.0.1. The flaw resides in the function formeditFileName located in the file /goform/editFileName. An attacker can manipulate the argument editNameMit to perform command injection attacks. The vulnerability is remotely exploitable, requiring no physical access to the device. A public exploit has already been released, increasing the risk of active exploitation. The affected product is a networking device manufactured by Tenda. This vulnerability poses a significant risk to users who have not applied patches or mitigations. The public availability of the exploit makes prompt action critical for affected device owners.