Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
2.1

CVE-2026-78063: Tenda CH22 router can run commands via file rename

CVE-2026-78063 · published 12 days ago
Summary

The Tenda CH22 router lets an attacker change a file name in a way that runs unauthorized commands on the device. This can be done from outside the network, giving a remote user control of the router. Update the router firmware to the latest version or apply the vendor's patch as soon as possible.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
tenda ch22 1.0.0.1
Original advisory text
Tenda CH22 editFileName formeditFileName command injection
A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the function formeditFileName of the file /goform/editFileName. The manipulation of the argument editNameMit results in command injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
Severity
2.1 Low
CVSS 3.1: 7.4 (MITRE)
Exploitation
EPSS 1%
Type
CWE-77Command Injection
CWE-74Injection
Timeline
Published23 Aug 2026
Updated30 Aug 2026
First seen23 Aug 2026
Sources
CVE-2026-78063 · MITRE
Monitor software like this
Free during beta