CVE-2026-5153

MEDIUM

Tenda CH22 WriteFacMac FormWriteFacMac command injection

Title source: cna

Description

A flaw has been found in Tenda CH22 1.0.0.1. The affected element is the function FormWriteFacMac of the file /goform/WriteFacMac. Executing a manipulation of the argument mac can lead to command injection. The attack may be launched remotely. The exploit has been published and may be used.

Scores

CVSS v3 6.3
EPSS 0.0084
EPSS Percentile 74.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Details

CWE
CWE-74 CWE-77
Status published
Products (2)
Tenda/CH22 1.0.0.1
tenda/ch22_firmware 1.0.0.1
Published Mar 30, 2026
Tracked Since Mar 31, 2026