Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.4

CVE-2026-19346: Tenda CH22: Remote Command Injection via Form Submission

CVE-2026-19346 · published 26 days ago
Summary

A vulnerability in the Tenda CH22 router's form submission feature allows attackers to inject malicious commands, potentially leading to unauthorized access or data tampering. This issue affects the device's security and can be exploited remotely. To mitigate this risk, update the router to the latest available version or consider replacing it if a patch is not available.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
tenda ch22 1.0.0.1
Original advisory text
A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formCertListInfo of the file /goform/CertListInfo. This manipulation of the argument Name causes comman...
A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formCertListInfo of the file /goform/CertListInfo. This manipulation of the argument Name causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.
Severity
7.4 High
CVSS 3.1: 8.8 (MITRE)
Exploitation
EPSS 2%
Type
CWE-77Command Injection
CWE-74Injection
Timeline
Published9 Aug 2026
Updated30 Aug 2026
First seen9 Aug 2026
Sources
CVE-2026-19346 · MITRE
Monitor software like this
Free during beta