GHSA-x5qw-fmv8-fhx9LowCVSS 7.4
A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the function...
🔗 CVE IDs covered (1)
📋 Description
A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the function formeditFileName of the file /goform/editFileName. The manipulation of the argument editNameMit results in command injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
🔗 References (8)
- https://nvd.nist.gov/vuln/detail/CVE-2026-78063
- https://candle-throne-f75.notion.site/Tenda-CH22-formeditFileName-396df0aa1185804c9dcff01778515d32
- https://vuldb.com/cve/CVE-2026-78063
- https://vuldb.com/submit/881838
- https://vuldb.com/vuln/394303
- https://vuldb.com/vuln/394303/cti
- https://www.tenda.com.cn
- https://github.com/advisories/GHSA-x5qw-fmv8-fhx9