Impact
A flaw in the formexeCommand function of Tenda CH22’s /goform/exeCommand file allows an attacker to manipulate the cmdinput argument and inject arbitrary operating‑system commands. This injection enables remote execution of commands, potentially compromising confidentiality, integrity, and availability of the device. The vulnerability does not require local access; it can be triggered through a remote HTTP request.
Affected Systems
The affected product is Tenda CH22, firmware version 1.0.0.1. Only this specific version is known to be vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but public exploits have been disclosed, meaning the attack could be attempted by adversaries who can reach the device’s web interface.
OpenCVE Enrichment