CVE-2026-78141

7.4

Tenda · CH22

The Tenda CH22 router contains a command injection vulnerability, allowing authenticated attackers to execute arbitrary system commands through the web interface.

Executive summary

A command injection vulnerability in Tenda CH22 firmware enables an authenticated attacker to execute arbitrary commands, posing a risk of full device compromise.

Vulnerability

The device is vulnerable to command injection (CWE-77) and injection (CWE-74) in its web interface. Exploitation requires the attacker to have low-level authenticated access to the management console to trigger the execution of malicious commands.

Business impact

The ability to inject commands allows an attacker to gain unauthorized control over the network hardware. This compromises the integrity and confidentiality of the device, potentially allowing for lateral movement within the network or interception of traffic, justifying the high CVSS score of 7.4.

Remediation

Immediate Action: Check the Tenda support portal for available firmware updates and apply them as soon as they become available.

Proactive Monitoring: Review device access logs for suspicious administrative activity or unusual shell command execution patterns originating from the management interface.

Compensating Controls: Restrict access to the management interface to trusted management IP addresses only and disable remote management features if they are not strictly required.

Exploitation status

Public Exploit Available: No (exploit_available unknown)

Analyst recommendation

Because this vulnerability allows for command injection, it represents a critical security failure for the affected hardware. Administrators should isolate the device management interface from untrusted networks and apply firmware patches immediately upon vendor release.

More Tenda CVEs