Description
A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the function formeditFileName of the file /goform/editFileName. The manipulation of the argument editNameMit results in command injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
Published: 2026-08-23
Score: 5.3 Medium
EPSS: 2.7% Low
KEV: No
Impact: Command injection allowing remote code execution
Action: Patch Now
AI Analysis

Impact

A flaw exists in the Tenda CH22 router firmware 1.0.0.1 that permits injection of arbitrary system commands via the editNameMit field of the /goform/editFileName endpoint. This weakness can cause unintended execution of commands on the device, potentially leading to unauthorized control or disruption of network services.

Affected Systems

The vulnerability applies to the Tenda CH22 router model running firmware version 1.0.0.1. No other firmware revisions or models are identified in the advisory. The associated CPE confirms that only this specific firmware is targeted.

Risk and Exploitability

The CVSS base score of 5.3 indicates moderate risk. The EPSS score of 3% reflects a low but non‑zero probability of exploitation. A public exploit has already been released, so attackers may be actively targeting the device. The vulnerability is not listed in the CISA KEV catalog, yet the documented exploitation code elevates the urgency for mitigation.

Generated by OpenCVE AI on September 25, 2026 at 00:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any firmware update from Tenda that addresses the command‑injection flaw as soon as it is released.
  • If no update is available, block external traffic to the /goform/editFileName endpoint or restrict administration to an internal network or VPN tunnel.
  • Implement input validation or escaping for the editNameMit parameter and enforce least privilege for any process that executes system commands on the router.

Generated by OpenCVE AI on September 25, 2026 at 00:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 23 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
First Time appeared Tenda ch22
Vendors & Products Tenda ch22

Sun, 23 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the function formeditFileName of the file /goform/editFileName. The manipulation of the argument editNameMit results in command injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
Title Tenda CH22 editFileName formeditFileName command injection
First Time appeared Tenda
Tenda ch22 Firmware
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:o:tenda:ch22_firmware:*:*:*:*:*:*:*:*
Vendors & Products Tenda
Tenda ch22 Firmware
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.4, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P'}


Subscriptions

Tenda Ch22 Ch22 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-24T15:13:50.632Z

Reserved: 2026-08-22T11:03:32.176Z

Link: CVE-2026-78063

cve-icon Vulnrichment

Updated: 2026-08-24T15:13:45.786Z

cve-icon NVD

Status : Deferred

Published: 2026-08-23T05:16:53.273

Modified: 2026-08-24T16:41:13.950

Link: CVE-2026-78063

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-25T01:00:13Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')