Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
2.1
CVE-2026-78063: Tenda CH22 router can run commands via file rename
CVE-2026-78063 · published 12 days ago
Summary
The Tenda CH22 router lets an attacker change a file name in a way that runs unauthorized commands on the device. This can be done from outside the network, giving a remote user control of the router. Update the router firmware to the latest version or apply the vendor's patch as soon as possible.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| tenda | ch22 | 1.0.0.1 |
Original advisory text
Tenda CH22 editFileName formeditFileName command injection
A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the function formeditFileName of the file /goform/editFileName. The manipulation of the argument editNameMit results in command injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
References
- https://vuldb.com/vuln/394303 vdb-entry technical-description
- https://vuldb.com/vuln/394303/cti signature permissions-required
- https://vuldb.com/cve/CVE-2026-78063 third-party-advisory
- https://vuldb.com/submit/881838 third-party-advisory
- https://candle-throne-f75.notion.site/Tenda-CH22-formeditFileName-396df0aa118580... exploit
- https://www.tenda.com.cn/ product
Severity
2.1
Low
CVSS 3.1: 7.4 (MITRE)
Exploitation
EPSS 1%
Type
CWE-77Command Injection
CWE-74Injection
Timeline
Published23 Aug 2026
Updated30 Aug 2026
First seen23 Aug 2026
Monitor software like this
Free during beta