Executive brief
Tenda CH22 is a network device used for connectivity and network management. A remote attacker can inject arbitrary commands through the exeCommand interface, allowing them to execute malicious code on the device and potentially take full control of the network infrastructure.
Technical details
This vulnerability is a command injection flaw in the formexeCommand function within the /goform/exeCommand endpoint of Tenda CH22 version 1.0.0.1. The cmdinput parameter is not properly sanitized, allowing an attacker to inject arbitrary shell commands. The vulnerability is remotely exploitable without authentication and can result in unauthenticated remote code execution with device-level privileges. The attack has been publicly disclosed.
Affected products
- Tenda CH22 1.0.0.1
Timeline
- 2026-08-23: disclosed: Public disclosure of vulnerability