CVE-2026-78141
published 2026-08-23CVE-2026-78141: A vulnerability has been found in Tenda CH22 1.0.0.1. This affects the function formexeCommand of the file /goform/exeCommand. The manipulation of the argument…
PriorityP179high7.4CVSS 3.1
AVNACLPRLUINSCCLILAL
ITWVulnCheck KEV
Exploited in the wild
EPSS
1.07%
63.3th percentile
A vulnerability has been found in Tenda CH22 1.0.0.1. This affects the function formexeCommand of the file /goform/exeCommand. The manipulation of the argument cmdinput leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| tenda | ch22 | — | — |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
nvdv4.02.1LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vulncheck7.4HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A vulnerability has been found in Tenda CH22 1.0.0.1.
ghsa_unreviewed·2026-08-24
CVE-2026-78141 [LOW] CWE-74 A vulnerability has been found in Tenda CH22 1.0.0.1.
A vulnerability has been found in Tenda CH22 1.0.0.1. This affects the function formexeCommand of the file /goform/exeCommand. The manipulation of the argument cmdinput leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
VulDB
Tenda CH22 1.0.0.1 /goform/exeCommand formexeCommand cmdinput command injection
vuldb·2026-08-23·CVSS 7.4
CVE-2026-78141 [HIGH] Tenda CH22 1.0.0.1 /goform/exeCommand formexeCommand cmdinput command injection
A vulnerability has been found in Tenda CH22 1.0.0.1 and classified as critical. This affects the function formexeCommand of the file /goform/exeCommand. The manipulation of the argument cmdinput leads to command injection.
This vulnerability is listed as CVE-2026-78141. The attack may be initiated remotely. In addition, an exploit is available.
VulnCheck
Tenda ch22_firmware Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
vulncheck·2026·CVSS 7.4
CVE-2026-78141 [HIGH] Tenda ch22_firmware Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Tenda ch22_firmware Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
A vulnerability has been found in Tenda CH22 1.0.0.1. This affects the function formexeCommand of the file /goform/exeCommand. The manipulation of the argument cmdinput leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected: Tenda ch22_firmware
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/map/?day=2026-09-01&host_type=src&vulnerability=cve-2026-78141; https://previdian.com/CVE-2026-78141
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-23
Published
Exploited in the wild