Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
2.1
CVE-2026-78141: Tenda CH22 router lets remote attackers run commands
CVE-2026-78141 · published 11 days ago
Summary
The Tenda CH22 router’s web interface contains a flaw that lets someone send specially crafted data to execute commands on the device. Because this can be done over the network, an attacker could gain control of the router or disrupt its operation. Update the firmware to the latest version or apply the vendor’s patch as soon as possible.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| tenda | ch22 | 1.0.0.1 |
Original advisory text
Tenda CH22 exeCommand formexeCommand command injection
A vulnerability has been found in Tenda CH22 1.0.0.1. This affects the function formexeCommand of the file /goform/exeCommand. The manipulation of the argument cmdinput leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity
2.1
Low
CVSS 2.0: 6.5 (NVD)
CVSS 3.1: 7.4 (NVD)
CVSS 4.0: 2.1 (NVD)
Exploitation
EPSS 1%
Type
CWE-74Injection
CWE-77Command Injection
Timeline
Published23 Aug 2026
Updated30 Aug 2026
First seen23 Aug 2026
Monitor software like this
Free during beta