CVE-2026-19346
8.8Tenda · CH22
A command injection vulnerability in Tenda CH22 allows authenticated attackers to execute arbitrary system commands via the formCertListInfo function.
Executive summary
A command injection vulnerability in the Tenda CH22 router, affecting version 1.0.0.1, presents a high risk of unauthorized system command execution.
Vulnerability
The device is susceptible to command injection (CWE-77) within the formCertListInfo function. This vulnerability requires the attacker to have low-level privileges (authenticated) to successfully trigger the injection.
Business impact
This vulnerability poses a significant risk to network integrity and confidentiality. A successful exploit allows an authenticated attacker to execute arbitrary commands on the underlying operating system, potentially leading to full device compromise. With a CVSS score of 8.8, this flaw is categorized as high severity, necessitating immediate attention to prevent unauthorized administrative access or lateral movement within the network.
Remediation
Immediate Action: Contact Tenda support or check the official Tenda website for firmware updates addressing the command injection flaw in version 1.0.0.1.
Proactive Monitoring: Review administrative access logs for unusual activity or unexpected command execution patterns originating from authenticated user sessions.
Compensating Controls: Restrict administrative access to the management console to trusted management VLANs or specific IP addresses to limit the attack surface.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high CVSS score and the nature of command injection, organizations should prioritize upgrading the affected Tenda CH22 devices as soon as a patch is made available by the vendor. In the interim, strictly enforce access control policies to ensure only authorized personnel can reach the management interface.