2026-08-23 21:45CVE-2026-78141VulDB
PUBLISHED5.2Operating systemCWE-77CWE-74

Tenda CH22 exeCommand formexeCommand command injection

A vulnerability has been found in Tenda CH22 1.0.0.1. This affects the function formexeCommand of the file /goform/exeCommand. The manipulation of the argument cmdinput leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

Problem type

Affected products

Tenda

CH22

1.0.0.1 - AFFECTED

References

GitHub Security Advisories

GHSA-9mvp-7535-p7rw

A vulnerability has been found in Tenda CH22 1.0.0.1. This affects the function formexeCommand of...

https://github.com/advisories/GHSA-9mvp-7535-p7rw

A vulnerability has been found in Tenda CH22 1.0.0.1. This affects the function formexeCommand of the file /goform/exeCommand. The manipulation of the argument cmdinput leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-78141
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-78141",
    "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
    "assignerShortName": "VulDB",
    "dateUpdated": "2026-08-23T21:45:09.069Z",
    "dateReserved": "2026-08-23T05:57:32.107Z",
    "datePublished": "2026-08-23T21:45:09.069Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "shortName": "VulDB",
        "dateUpdated": "2026-08-23T21:45:09.069Z"
      },
      "title": "Tenda CH22 exeCommand formexeCommand command injection",
      "descriptions": [
        {
          "lang": "en",
          "value": "A vulnerability has been found in Tenda CH22 1.0.0.1. This affects the function formexeCommand of the file /goform/exeCommand. The manipulation of the argument cmdinput leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used."
        }
      ],
      "affected": [
        {
          "vendor": "Tenda",
          "product": "CH22",
          "cpes": [
            "cpe:2.3:o:tenda:ch22_firmware:*:*:*:*:*:*:*:*"
          ],
          "versions": [
            {
              "version": "1.0.0.1",
              "status": "affected"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "Command Injection",
              "cweId": "CWE-77",
              "type": "CWE"
            }
          ]
        },
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "Injection",
              "cweId": "CWE-74",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://vuldb.com/vuln/394524",
          "name": "VDB-394524 | Tenda CH22 exeCommand formexeCommand command injection",
          "tags": [
            "vdb-entry",
            "technical-description"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/394524/cti",
          "name": "VDB-394524 | CTI Indicators (IOB, IOC, TTP, IOA)",
          "tags": [
            "signature",
            "permissions-required"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-78141",
          "name": "CVE-2026-78141 | CVE Analysis and Report",
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/882284",
          "name": "Submit #882284 | Tenda CH22 V1.0.0.1 Command Injection",
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://candle-throne-f75.notion.site/Tenda-CH22-formexeCommand-396df0aa11858036b0cdf7a7562d4a67",
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "https://www.tenda.com.cn/",
          "tags": [
            "product"
          ]
        }
      ],
      "metrics": [
        {},
        {
          "cvssV3_1": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L/E:P/RL:X/RC:R",
            "baseScore": 7.4,
            "baseSeverity": "HIGH"
          }
        },
        {
          "cvssV3_0": {
            "version": "3.0",
            "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L/E:P/RL:X/RC:R",
            "baseScore": 7.4,
            "baseSeverity": "HIGH"
          }
        },
        {
          "cvssV2_0": {
            "version": "2.0",
            "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
            "baseScore": 6.5
          }
        }
      ],
      "timeline": [
        {
          "time": "2026-08-23T00:00:00.000Z",
          "lang": "en",
          "value": "Advisory disclosed"
        },
        {
          "time": "2026-08-23T02:00:00.000Z",
          "lang": "en",
          "value": "VulDB entry created"
        },
        {
          "time": "2026-08-23T08:02:38.000Z",
          "lang": "en",
          "value": "VulDB entry last update"
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "ysnysnysn (VulDB User)",
          "type": "reporter"
        }
      ]
    }
  }
}