Executive brief
Tenda CH22 is a networking device used for connectivity and network management. A vulnerability in its web management interface allows remote attackers to inject arbitrary commands by manipulating the fileName parameter, potentially enabling full device compromise without authentication.
Technical details
The vulnerability is a command injection flaw in the formcreateFileName function of the /goform/formcreateFileName endpoint on Tenda CH22 version 1.0.0.1. The fileNameMit parameter is not properly sanitized before being used in a system command, allowing an unauthenticated remote attacker to inject arbitrary shell commands. An attacker can exploit this by sending a crafted HTTP request with malicious payload in the fileName parameter to achieve remote code execution on the device. No patch information is currently available in the advisory.
Affected products
- Tenda CH22 1.0.0.1
Timeline
- 2026-08-20: disclosed