Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.4
CVE-2026-19346: Tenda CH22: Remote Command Injection via Form Submission
CVE-2026-19346 · published 26 days ago
Summary
A vulnerability in the Tenda CH22 router's form submission feature allows attackers to inject malicious commands, potentially leading to unauthorized access or data tampering. This issue affects the device's security and can be exploited remotely. To mitigate this risk, update the router to the latest available version or consider replacing it if a patch is not available.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| tenda | ch22 | 1.0.0.1 |
Original advisory text
A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formCertListInfo of the file /goform/CertListInfo. This manipulation of the argument Name causes comman...
A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formCertListInfo of the file /goform/CertListInfo. This manipulation of the argument Name causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.
References
- https://vuldb.com/vuln/387182 vdb-entry technical-description
- https://vuldb.com/vuln/387182/cti signature permissions-required
- https://vuldb.com/cve/CVE-2026-19346 third-party-advisory
- https://vuldb.com/submit/865530 third-party-advisory
- https://candle-throne-f75.notion.site/Tenda-CH22-formCertListInfo-387df0aa118580... exploit
- https://www.tenda.com.cn/ product
Severity
7.4
High
CVSS 3.1: 8.8 (MITRE)
Exploitation
EPSS 2%
Type
CWE-77Command Injection
CWE-74Injection
Timeline
Published9 Aug 2026
Updated30 Aug 2026
First seen9 Aug 2026
Monitor software like this
Free during beta