CVE-2026-78063: Tenda CH22 editFileName formeditFileName command injection
A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the function formeditFileName of the file /goform/editFileName. The manipulation of the argument editNameMit results in command injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attack can be launched remotely, but the CVSS vector indicates that the attacker needs low-level privileges. No user interaction is required.
Which component and input should defenders investigate?
The affected endpoint is /goform/editFileName, specifically the formeditFileName function. The editNameMit argument is the input reported to allow command injection.
How likely is exploitation?
Public exploit code has been released, so the issue may be used in attacks. The vulnerability is rated high severity with a CVSS score of 7.4.