Description
A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the function formeditFileName of the file /goform/editFileName. The manipulation of the argument editNameMit results in command injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
Published: 2026-08-23
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw exists in the Tenda CH22 router that allows injection of arbitrary system commands through the editNameMit parameter of the /goform/editFileName endpoint. This command‑injection weakness (CWE-74 and CWE-77) can be exploited from a remote address, potentially granting an attacker full control over the device or causing a denial of service. The description does not explicitly state the extent of damage, but based on the nature of command injection, it is inferred that an attacker could execute any privileged command available to the router’s operating system.

Affected Systems

The vulnerability applies to the Tenda CH22 router running firmware version 1.0.0.1. The CPE identifier confirms that this specific firmware is targeted. No additional firmware revisions or models are mentioned as affected in the advisory.

Risk and Exploitability

The severity rating of 5.3 on the CVSS base vector indicates moderate risk. The EPSS score is unavailable, yet the advisory notes that a public exploit has been released, implying a non‑negligible likelihood of real‑world attacks. Because the attack vector is a remotely accessible HTTP interface, attackers can reach the vulnerable payload without any privileged network position. The vulnerability is not yet tracked in the CISA KEV catalog, but the public availability of exploitation code raises the priority for immediate assessment and mitigation.

Generated by OpenCVE AI on August 23, 2026 at 06:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Tenda’s publisher portal for a firmware update that addresses the command‑injection flaw and deploy it without delay.
  • If no patch is yet available, block external traffic to the /goform/editFileName endpoint and limit administrator access to the internal network or a VPN tunnel only.
  • Introduce strict input validation or escaping for the editNameMit parameter, and apply the principle of least privilege to processes that run firmware commands.

Generated by OpenCVE AI on August 23, 2026 at 06:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 23 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
First Time appeared Tenda ch22
Vendors & Products Tenda ch22

Sun, 23 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the function formeditFileName of the file /goform/editFileName. The manipulation of the argument editNameMit results in command injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
Title Tenda CH22 editFileName formeditFileName command injection
First Time appeared Tenda
Tenda ch22 Firmware
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:o:tenda:ch22_firmware:*:*:*:*:*:*:*:*
Vendors & Products Tenda
Tenda ch22 Firmware
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.4, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P'}


Subscriptions

Tenda Ch22 Ch22 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-23T04:30:10.230Z

Reserved: 2026-08-22T11:03:32.176Z

Link: CVE-2026-78063

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-23T05:16:53.273

Modified: 2026-08-23T05:16:53.273

Link: CVE-2026-78063

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-23T06:30:16Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')