CVE-2026-78141: Tenda CH22 exeCommand formexeCommand command injection
Published Aug 23, 2026
·Updated
A vulnerability has been found in Tenda CH22 1.0.0.1. This affects the function formexeCommand of the file /goform/exeCommand. The manipulation of the argument cmdinput leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
1 affected component
Tenda CH22=1.0.0.1
Event History
Aug 23, 2026
CVE Published
via MITRE·09:45 PM
Data Sourced
via MITRE·09:45 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The vulnerability can be initiated remotely and requires low privileges. No user interaction is required.
2
Which component and input are affected?
The affected endpoint is /goform/exeCommand, specifically the formexeCommand function. Command injection occurs through manipulation of the cmdinput argument.
3
Is public exploit information available?
Yes. The exploit has been publicly disclosed and may be used.