CVE-2026-78063
7.4Tenda · CH22
A command injection vulnerability in the Tenda CH22 router allows authenticated attackers to execute arbitrary system commands via the formEditFileName function.
Executive summary
A command injection flaw in the Tenda CH22 router, version 1.0.0.1, presents a high risk of unauthorized system command execution by authenticated users.
Vulnerability
This vulnerability is a command injection flaw (CWE-77) triggered through the formEditFileName function. The CVSS vector confirms that an attacker must possess low-level privileges to successfully execute arbitrary commands on the affected device.
Business impact
Successful exploitation allows an attacker to gain unauthorized control over the network device, potentially leading to a complete compromise of the router. Given the CVSS score of 7.4, this vulnerability poses a significant threat to internal network security, as attackers could intercept traffic, modify configurations, or pivot to other systems on the network.
Remediation
Immediate Action: Contact Tenda support or monitor the official Tenda website for a firmware update that addresses the command injection vulnerability in the CH22 model.
Proactive Monitoring: Inspect system logs for unusual administrative activity or unexpected shell command execution patterns originating from authenticated sessions.
Compensating Controls: Restrict access to the device management interface to trusted administrative IP addresses only, and enforce strong password policies for all authenticated users to limit the potential for unauthorized privilege acquisition.
Exploitation status
Public Exploit Available: No (unknown)
Analyst recommendation
Due to the severity of command injection vulnerabilities, it is critical to prioritize the installation of vendor-provided patches as soon as they become available. Until an update is released, administrators should strictly limit access to the device management interface to minimize the attack surface.