A vulnerability marked as critical has been reported in Tenda CH22 1.0.0.1. This vulnerability affects the function
formCertListInfo of the file /goform/CertListInfo. This manipulation of the argument Name causes command injection.
This vulnerability is handled as CVE-2026-19346. The attack can be initiated remotely. Additionally, an exploit exists.