Product
high
advisory
Remote Command Injection in Tenda CH22 Firmware
2 rules 3 TTPs 1 CVETenda CH22 router firmware version 1.0.0.1 is vulnerable to unauthenticated remote command injection via the /goform/editFileName endpoint, allowing potential full system compromise.
CH22 +1
remote-code-execution
command-injection
network-device
2r
3t
1c
updated
high
advisory
Tenda CH22 Path Traversal Vulnerability (CVE-2026-5962)
2 rules 1 TTP 1 CVEA path traversal vulnerability exists in Tenda CH22 version 1.0.0.6(468), affecting the R7WebsSecurityHandler function within the httpd component, allowing remote attackers to access sensitive files.
CH22
cve-2026-5962
path-traversal
tenda
router
2r
1t
1c