Skip to content
EXPLOIT
.CC
CVEs
Search
About
synced 42 MIN AGO
T-42M
01
Record
STATE: —
02
Description
SRC: CNA
03
Metadata
SCHEMA: CVE JSON 5
04
Affected products
PAIRS: —
05
References
REFS: —
01
Record
STATE: PUBLISHED
CVE-2026-77031
Tenda CH22 formcreateFileName command injection
Medium
PUBLISHED
CNA: VulDB
Base score
5.3
CVSS v4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P
View raw JSON
CVE Program record
02
Description
CNA: VulDB
Tenda CH22 formcreateFileName command injection
03
Metadata
SCHEMA: 5.2
Published
2026-08-20 17:15Z
1 DAY AGO
Last updated
2026-08-20 18:28Z
1 DAY AGO
Reserved
2026-08-20
Assigning CNA
VulDB
Record state
PUBLISHED
Severity
Medium (CVSS 5.3)
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P
Weaknesses
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Class
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
Class
SSVC decision
Exploitation
poc
Automatable
no
Technical Impact
partial
Data version
5.2
Document digest
2c46cbc6f96d3f7a0975c1f501882e872a27fa9075a064b875c489489f0110d3
04
Affected products
PAIRS: 1
Vendor
Product
Versions
Platforms
Tenda
CH22
1.0.0.1
—
05
References
REFS: 6
vuldb.com
VDB-393642 | Tenda CH22 formcreateFileName command injection
https://vuldb.com/vuln/393642
vdb-entry
technical-description
vuldb.com
VDB-393642 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/393642/cti
signature
permissions-required
vuldb.com
CVE-2026-77031 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-77031
third-party-advisory
vuldb.com
Submit #880667 | Tenda CH22 V1.0.0.1 Command Injection
https://vuldb.com/submit/880667
third-party-advisory
candle-throne-f75.notion.site
https://candle-throne-f75.notion.site/Tenda-CH22-formcreateFileName-392df0aa118580c38c4ad15fb15cd30d
exploit
www.tenda.com.cn
https://www.tenda.com.cn/
product