CVE-2026-19346
Received Received - Intake

Command Injection in Tenda CH22 Router

Vulnerability report for CVE-2026-19346, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-09

Last updated on: 2026-08-09

Assigner: VulDB

Description

A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formCertListInfo of the file /goform/CertListInfo. This manipulation of the argument Name causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-09
Last Modified
2026-08-09
Generated
2026-08-09
AI Q&A
2026-08-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
tenda ch22 1.0.0.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-77 The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CWE-74 The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a command injection flaw in Tenda CH22 version 1.0.0.1. It exists in the function formCertListInfo within the file /goform/CertListInfo. An attacker can exploit this by manipulating the Name argument to inject and execute arbitrary commands remotely.

Detection Guidance

Detecting this vulnerability requires checking for command injection attempts targeting the Tenda CH22 device via the /goform/CertListInfo endpoint. Monitor network traffic for unusual requests to this path with suspicious payloads in the Name parameter. Inspect device logs for signs of unauthorized command execution or unexpected system behavior.

Impact Analysis

This vulnerability allows remote attackers to execute arbitrary commands on the affected device. This could lead to unauthorized access, data theft, or complete device compromise. Attackers may gain control over the router, intercept traffic, or use it as a pivot point for further attacks.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, which may violate GDPR and HIPAA requirements for data protection and confidentiality. Organizations using this device may face compliance violations, legal penalties, and reputational damage if exploited.

Mitigation Strategies

Immediately isolate the affected Tenda CH22 device from your network to prevent exploitation. Apply firmware updates if available from the vendor. Disable remote access to the device if not required. Monitor for any signs of compromise and consider replacing the device if no patch is provided.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19346. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart