Impact
The vulnerability resides in the formCertListInfo function of the /goform/CertListInfo endpoint in Tenda CH22 firmware 1.0.0.1. By manipulating the Name argument, an attacker can inject arbitrary system commands, leading to full remote command execution on the device. The weakness is a classic Command Injection flaw (CWE-74) that allows arbitrary commands to be executed with the privileges of the web service process.
Affected Systems
Affected is the Tenda CH22 router running firmware version 1.0.0.1. No other product versions are listed, so the risk is confined to installations of this specific firmware.
Risk and Exploitability
The CVSS score is 8.7, indicating a high severity. EPSS is not available, so current exploitation probability is unknown. The vulnerability can be exploited from outside the local network via HTTP requests to the router’s web interface. Since it is not listed in CISA KEV, no active exploitation campaigns are reported yet, but the public disclosure suggests potential use. The attack requires only network access to the router’s management interface and no special credentials.
OpenCVE Enrichment