Command Injection Vulnerability in Tenda CH22 Router
CVE-2026-78063
Key Information:
Badges
What is CVE-2026-78063?
A command injection vulnerability exists in the Tenda CH22 router, specifically in the formeditFileName function located in the /goform/editFileName file. This flaw allows an attacker to manipulate the editNameMit argument, enabling the execution of arbitrary commands remotely. The exploit has been publicly disclosed, raising concerns about potential unauthorized access and control over affected systems. It is crucial for users of the Tenda CH22 router to take immediate action to mitigate this vulnerability and secure their devices.
Affected Version(s)
CH22 1.0.0.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved