CVE-2026-19346

Summary

A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formCertListInfo of the file /goform/CertListInfo. This manipulation of the argument Name causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.

Affected Software

VendorProductVersion RangeStatus
TendaCH221.0.0.1affected

Weaknesses

  • CWE-77: Command Injection
  • CWE-74: Injection

References