CVE-2026-77031: Tenda CH22 formcreateFileName command injection
Published Aug 20, 2026
·Updated
A vulnerability has been found in Tenda CH22 1.0.0.1. The affected element is the function formcreateFileName of the file /goform/formcreateFileName. The manipulation of the argument fileNameMit leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
1 affected component
Tenda CH22=1.0.0.1
Event History
Aug 20, 2026
CVE Published
via MITRE·05:15 PM
Data Sourced
via MITRE·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The attack can be initiated remotely and has low attack complexity, but it requires low-level privileges. No user interaction is required.
2
Which systems are known to be affected?
The provided information identifies Tenda CH22 version 1.0.0.1 as affected. The vulnerable endpoint is /goform/formcreateFileName, specifically its fileNameMit argument.
3
Is public exploit information available?
Yes. The exploit has been publicly disclosed and may be used.