CVE-2026-19346

8.8

Tenda · CH22

A command injection vulnerability in Tenda CH22 allows authenticated attackers to execute arbitrary system commands via the formCertListInfo function.

Executive summary

A command injection vulnerability in the Tenda CH22 router, affecting version 1.0.0.1, presents a high risk of unauthorized system command execution.

Vulnerability

The device is susceptible to command injection (CWE-77) within the formCertListInfo function. This vulnerability requires the attacker to have low-level privileges (authenticated) to successfully trigger the injection.

Business impact

This vulnerability poses a significant risk to network integrity and confidentiality. A successful exploit allows an authenticated attacker to execute arbitrary commands on the underlying operating system, potentially leading to full device compromise. With a CVSS score of 8.8, this flaw is categorized as high severity, necessitating immediate attention to prevent unauthorized administrative access or lateral movement within the network.

Remediation

Immediate Action: Contact Tenda support or check the official Tenda website for firmware updates addressing the command injection flaw in version 1.0.0.1.

Proactive Monitoring: Review administrative access logs for unusual activity or unexpected command execution patterns originating from authenticated user sessions.

Compensating Controls: Restrict administrative access to the management console to trusted management VLANs or specific IP addresses to limit the attack surface.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS score and the nature of command injection, organizations should prioritize upgrading the affected Tenda CH22 devices as soon as a patch is made available by the vendor. In the interim, strictly enforce access control policies to ensure only authorized personnel can reach the management interface.

More Tenda CVEs