← Terug naar overzicht

A critical security vulnerability has been identified in Tenda CH22 firmware version 1.0.0.1. The flaw resides in the function formeditFileName located in the file /goform/editFileName. An attacker can manipulate the argument editNameMit to perform command injection attacks. The vulnerability is remotely exploitable, requiring no physical access to the device. A public exploit has already been released, increasing the risk of active exploitation. The affected product is a networking device manufactured by Tenda. This vulnerability poses a significant risk to users who have not applied patches or mitigations. The public availability of the exploit makes prompt action critical for affected device owners.

Affected products

  • Tenda CH22 1.0.0.1

Related CVE's

  • CVE-2026-78063

Categories

  • Mobile & IoT
  • Network Infrastructure
  • Zero-Day Vulnerabilities