Remote command injection in Tenda CH22

Note: This data is for reference and cybersecurity research purposes only.CyStack advises users not to use this information for unlawful purposes.

What is CVE-2026-78141?

CVE-2026-78141 is a vulnerability classified as Improper Neutralization of Special Elements used in a Command ('Command Injection') and Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), affecting CH22 (affected versions: 1.0.0.1). This vulnerability is rated Medium, with a CVSS score of 5.3. Public exploit code or evidence is available for this vulnerability, but that does not confirm exploitation in the wild.

Overview

Original source data

A vulnerability has been found in Tenda CH22 1.0.0.1. This affects the function formexeCommand of the file /goform/exeCommand. The manipulation of the argument cmdinput leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

Affected products and scope

  • Tenda CH22 firmware 1.0.0.1 is identified as affected.
  • The relevant component is the formexeCommand function at /goform/exeCommand.
  • The record does not identify a fixed release, additional affected branch, or confirmed unaffected parallel branch. Other versions should not be assumed safe from the available evidence alone.

Technical details

The vulnerable component is the formexeCommand function in /goform/exeCommand. The cmdinput argument can be influenced by attacker-controlled data. The source classifies the issue as CWE-77 and CWE-74, indicating that special elements may not be properly neutralized before the data is passed into downstream command processing.

At a high level, the described attack flow is:

  1. A remote request reaches the formexeCommand handler.
  2. Data in cmdinput is passed into processing.
  3. Special elements in that data can alter the intended command.
  4. The device may execute an unintended command.

The returned evidence does not document the command template, parser, process privileges, exact authentication workflow, or response behavior. Payloads and post-exploitation control should therefore not be inferred.

Exploitability

  • Reachability: The issue is remotely network reachable; the available evidence does not require local or physical access.
  • Preconditions: The supplied assessment indicates that low privileges are required and that no user interaction is needed. The exact authentication workflow is not documented.
  • Complexity: The available assessment describes attack complexity as low.
  • Status: A public exploit and proof-of-concept are reported. CISA ADP data returned through the GCVE source characterizes exploitation as proof-of-concept and the activity as not automatable.

The supplied evidence does not name a specific campaign, victim, or ransomware use.

Technical impact

The direct technical outcome is unintended command execution through the device's web handling path. This could permit unauthorized changes, access to device-managed data, or disruption of network service, depending on the privileges of the executing process and the device configuration.

The available information describes possible effects on confidentiality, integrity, and availability, and one assessment model indicates that impact may extend beyond the vulnerable component. The record does not confirm persistence, lateral movement, or compromise of other devices.

Business impact

Successful exploitation could cause the device to execute unintended commands in its own security context. Depending on process privileges and device configuration, this could affect the confidentiality, integrity, or availability of device-held data and network operations.

Possible consequences include configuration changes, disclosure of information stored or handled by the device, or service disruption, but the available evidence does not confirm a particular breach or outage. Organizations should prioritize devices whose management interface or affected endpoint is exposed to untrusted networks.

Remediation

  1. Inventory Tenda CH22 devices and identify those running firmware 1.0.0.1; treat them as affected assets.
  2. No specific fixed release is provided in the record. Do not treat an unverified later release as safe; obtain vendor-confirmed update or replacement guidance.
  3. Until confirmed remediation is available, as a precaution, remove the management interface and affected endpoint from untrusted network reachability and restrict administrative access to trusted management networks. This reduces remote reachability but does not correct the injection.
  4. VulDB reports that no specific countermeasure is known and suggests that replacing the affected device with an alternative product may be considered. If a confirmed fix cannot be applied, evaluate replacement through the organization's asset and risk management process.
  5. After updating or replacing the device, recheck the firmware, management exposure, and configuration changes before returning it to production service.

Detection

  1. Inventory Tenda CH22 devices and identify their firmware. Devices running 1.0.0.1 should be treated as affected.
  2. Check whether the device management interface is reachable from untrusted networks, with particular attention to /goform/exeCommand.
  3. Review administrative or web server logs for requests to /goform/exeCommand and unusual values in cmdinput. This is a precautionary review, not a confirmed indicator of compromise.
  4. Correlate such requests with unexpected configuration changes, unusual command behavior, reboots, or service disruption. These are investigation leads, not proof of exploitation by themselves.
  5. Do not treat the absence of matching log entries as proof of safety, because the available evidence does not establish the product's logging format or coverage.
Sources (20)
Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan