CVE-2026-5962: Tenda CH22 httpd R7WebsSecurityHandlerfunction path traversal
A vulnerability was detected in Tenda CH22 1.0.0.6(468). This issue affects the function R7WebsSecurityHandlerfunction of the component httpd. The manipulation results in path traversal. The attack may be launched remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5962?
CVE-2026-5962 has a high severity due to the potential for remote exploitation through path traversal.
How do I fix CVE-2026-5962?
To fix CVE-2026-5962, it is recommended to update the Tenda CH22 firmware to the latest version provided by the vendor.
What is affected by CVE-2026-5962?
CVE-2026-5962 affects Tenda CH22 version 1.0.0.6(468) due to a vulnerability in the R7WebsSecurityHandlerfunction.
Can CVE-2026-5962 be exploited remotely?
Yes, CVE-2026-5962 can be exploited remotely, allowing attackers to manipulate file paths.
What type of vulnerability is CVE-2026-5962?
CVE-2026-5962 is a path traversal vulnerability found in the httpd component of Tenda CH22.