Junglewise Threat Intelligence

CVE-2026-78063: Tenda CH22 command injection in editFileName

CVE-2026-78063 · Severity: high · CVSS 7.4 · Published 2026-08-23

Technologies: Tenda CH22. Vendors: Tenda.

Executive brief

Tenda CH22 is a network management appliance. A flaw in the file editing function allows an attacker to inject arbitrary system commands by manipulating input parameters, potentially leading to full device compromise or service disruption.

Technical details

The vulnerability is a command injection flaw in the formeditFileName function of the /goform/editFileName endpoint in Tenda CH22 version 1.0.0.1. The editNameMit argument is insufficiently sanitized, permitting an attacker to inject shell commands that execute with device privileges. The attack vector is network-based and requires no authentication or user interaction. Successful exploitation allows remote code execution on the device. A public exploit is available.

Affected products

  • Tenda CH22 1.0.0.1

Timeline

  • 2026-08-23: disclosed

References

Related threats