Junglewise Threat Intelligence

CVE-2026-78141: Tenda CH22 command injection in formexeCommand

CVE-2026-78141 · Severity: high · CVSS 7.4 · Published 2026-08-23

Technologies: Tenda CH22. Vendors: Tenda.

Executive brief

Tenda CH22 is a network device used for connectivity and network management. A remote attacker can inject arbitrary commands through the exeCommand interface, allowing them to execute malicious code on the device and potentially take full control of the network infrastructure.

Technical details

This vulnerability is a command injection flaw in the formexeCommand function within the /goform/exeCommand endpoint of Tenda CH22 version 1.0.0.1. The cmdinput parameter is not properly sanitized, allowing an attacker to inject arbitrary shell commands. The vulnerability is remotely exploitable without authentication and can result in unauthenticated remote code execution with device-level privileges. The attack has been publicly disclosed.

Affected products

  • Tenda CH22 1.0.0.1

Timeline

  • 2026-08-23: disclosed: Public disclosure of vulnerability

References

Related threats