CVE-2026-19346: Tenda CH22 CertListInfo formCertListInfo command injection
Published Aug 9, 2026
·Updated
A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formCertListInfo of the file /goform/CertListInfo. This manipulation of the argument Name causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
1 affected component
Tenda CH22=1.0.0.1
Event History
Aug 9, 2026
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-19346?
The severity of CVE-2026-19346 is high, with a score of 8.8.
2
What type of vulnerability is CVE-2026-19346?
CVE-2026-19346 is a command injection vulnerability affecting the Tenda CH22.
3
How can an attacker exploit CVE-2026-19346?
An attacker can exploit CVE-2026-19346 remotely by manipulating the Name argument in the formCertListInfo function.
4
How do I fix CVE-2026-19346?
To fix CVE-2026-19346, apply the latest firmware update provided by Tenda for the CH22 model.
5
Is CVE-2026-19346 publicly disclosed?
Yes, CVE-2026-19346 has been publicly disclosed.