Executive brief
Tenda CH22 is a network management appliance. A flaw in the file editing function allows an attacker to inject arbitrary system commands by manipulating input parameters, potentially leading to full device compromise or service disruption.
Technical details
The vulnerability is a command injection flaw in the formeditFileName function of the /goform/editFileName endpoint in Tenda CH22 version 1.0.0.1. The editNameMit argument is insufficiently sanitized, permitting an attacker to inject shell commands that execute with device privileges. The attack vector is network-based and requires no authentication or user interaction. Successful exploitation allows remote code execution on the device. A public exploit is available.
Affected products
- Tenda CH22 1.0.0.1
Timeline
- 2026-08-23: disclosed