What is CVE-2026-19346?
A command injection vulnerability was found in Tenda CH22 router firmware version 1.0.0.1, affecting the `formCertListInfo` function in `/goform/CertListInfo` via improper handling of the `Name` argument. The attack can be initiated remotely, and a public exploit is available. Affected devices should be patched or isolated from the network until a fix is provided.
Azərbaycanca: Bu zəiflik Tenda CH22 router-in 1.0.0.1 versiyasında aşkarlanıb və `/goform/CertListInfo` faylındakı `formCertListInfo` funksiyasında `Name` parametrinin düzgün yoxlanılmaması səbəbindən command injection imkanı yaradır. Hücum uzaqdan həyata keçirilə bilər, istismar kodu açıqlanıb. Təsirlənən cihazların proqram təminatını yeniləmək və ya istehsalçı tərəfindən yamaq təqdim olunana qədər cihazı şəbəkədən təcrid etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-77
FAQ2
In which version of the Tenda CH22 router was CVE-2026-19346 found?
This vulnerability was found in version 1.0.0.1 of the Tenda CH22 router.
Is there a public exploit available for CVE-2026-19346?
Yes, a public exploit is available for this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.