Impact
A flaw exists in the Tenda CH22 router firmware 1.0.0.1 that permits injection of arbitrary system commands via the editNameMit field of the /goform/editFileName endpoint. This weakness can cause unintended execution of commands on the device, potentially leading to unauthorized control or disruption of network services.
Affected Systems
The vulnerability applies to the Tenda CH22 router model running firmware version 1.0.0.1. No other firmware revisions or models are identified in the advisory. The associated CPE confirms that only this specific firmware is targeted.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate risk. The EPSS score of 3% reflects a low but non‑zero probability of exploitation. A public exploit has already been released, so attackers may be actively targeting the device. The vulnerability is not listed in the CISA KEV catalog, yet the documented exploitation code elevates the urgency for mitigation.
OpenCVE Enrichment