CVE-2026-78141 carries a CVSS 3.1 base score of 7.4 against Tenda CH22 router firmware version 1.0.0.1. NVD classifies it under both CWE-74 and CWE-77 (command injection). NVD’s own description states that a public exploit for this flaw already exists and may be in use. VulnCheck’s KEV feed separately reports the CVE as exploited, dated September 1, 2026.
That exploitation report is single-sourced. CISA has not added CVE-2026-78141 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion. No Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.
What the flaw is
NVD’s description states the vulnerability affects the formexeCommand function in the router’s /goform/exeCommand endpoint, where manipulation of the cmdinput argument leads to command injection. NVD states the attack can be initiated remotely. NVD does not provide the specific crafted request needed to trigger the injection beyond identifying the vulnerable function and parameter.
Evidence and confidence
- Medium confidence — the CVSS 7.4 score, the vector (
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L), the CWE-74/CWE-77 classification, and the affected function/parameter, which trace to NVD alone in our current ingestion. The VulnCheck exploitation report is single-sourced, though NVD’s own text independently confirms public exploit availability. - Above-midpoint exploitation probability — FIRST’s EPSS model scores this CVE at 0.01067, a 63.1st percentile score as of our ingestion.
No field is in conflict between our two sources.
Why this matters
Consumer and small-office router firmware vulnerabilities like this one are attractive targets for botnet operators because affected devices are numerous, frequently unpatched for the lifetime of the hardware, and often internet-facing by design. NVD’s own confirmation that a public exploit already exists — independent of VulnCheck’s KEV listing — means the barrier to exploitation is low for anyone motivated to target Tenda CH22 devices; owners of this router model should check for a firmware update regardless of whether they consider themselves a likely target.
Frequently Asked Questions
What is CVE-2026-78141?
A CVSS 7.4 command injection vulnerability (CWE-74/CWE-77) in the formexeCommand function of Tenda CH22 router firmware version 1.0.0.1, exploitable via the cmdinput parameter of the /goform/exeCommand endpoint.
Is CVE-2026-78141 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated September 1, 2026, and NVD’s own description separately confirms a public exploit exists. CISA has not listed this CVE in its own Known Exploited Vulnerabilities catalog as of our current ingestion.
Do I need low privileges to exploit this?
Per the CVSS vector, yes — PR:L indicates low privileges are required, though NVD’s description states the attack can be initiated remotely.
Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.
Which version fixes this? Our source data does not carry a fixed-version field. Consult Tenda’s own site for firmware update availability for the CH22 model.
Severity, vector, weakness classification, and the affected function/parameter sourced from the National Vulnerability Database record for CVE-2026-78141, which also confirms public exploit availability. Exploitation status and the September 1, 2026 catalog date reported by VulnCheck KEV. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our current ingestion. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.