Junglewise Threat Intelligence

CVE-2026-77031: Tenda CH22 command injection in formcreateFileName

CVE-2026-77031 · Severity: high · CVSS 7.4 · Published 2026-08-20

Technologies: Tenda CH22. Vendors: Tenda.

Executive brief

Tenda CH22 is a networking device used for connectivity and network management. A vulnerability in its web management interface allows remote attackers to inject arbitrary commands by manipulating the fileName parameter, potentially enabling full device compromise without authentication.

Technical details

The vulnerability is a command injection flaw in the formcreateFileName function of the /goform/formcreateFileName endpoint on Tenda CH22 version 1.0.0.1. The fileNameMit parameter is not properly sanitized before being used in a system command, allowing an unauthenticated remote attacker to inject arbitrary shell commands. An attacker can exploit this by sending a crafted HTTP request with malicious payload in the fileName parameter to achieve remote code execution on the device. No patch information is currently available in the advisory.

Affected products

  • Tenda CH22 1.0.0.1

Timeline

  • 2026-08-20: disclosed

References

Related threats