CVE-2026-5153 carries a CVSS 3.1 base score of 6.3 against Tenda CH22 router firmware version 1.0.0.1. NVD classifies it as CWE-74/CWE-77 (Injection/Command Injection). VulnCheck’s KEV feed reports the CVE as exploited, dated September 1, 2026.
That exploitation report is single-sourced. CISA has not added CVE-2026-5153 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion. No Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.
What the flaw is
Per NVD, the flaw affects a MAC-address-writing function reachable through the router’s /goform/ web endpoint family. A request parameter representing a MAC address is passed to that function without adequate sanitization, and manipulating it results in command injection. NVD states the attack can be launched remotely and that this flaw has already been publicly disclosed with working reproduction material.
Evidence and confidence
- Medium confidence — the CVSS 6.3 score, the vector (
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L), the CWE-74/CWE-77 classification, and the described mechanism all trace to NVD alone in our current ingestion, corroborated by a VulDB catalog entry. The exploitation report traces to VulnCheck KEV alone. - High exploitation probability — FIRST’s EPSS model scores this CVE at 0.03298, an 87.9th percentile score as of our ingestion.
No field is in conflict between our two sources. Our source data does not carry a fixed-version field.
Why this matters
This is the second Tenda CH22 command-injection CVE we’ve covered from this KEV batch, following CVE-2026-78141 in an earlier round — a different vulnerable function on the same firmware and model, both reaching arbitrary command execution through an unsanitized configuration parameter. Two independently discovered, independently KEV-listed command-injection flaws in the same firmware image within weeks of each other is a strong signal that the device’s configuration-handling code has a systemic sanitization gap rather than one isolated bug. Owners of Tenda CH22 routers should check for a firmware update covering both CVEs and, in the interim, keep the router’s management interface off the public internet.
Frequently Asked Questions
What is CVE-2026-5153?
A CVSS 6.3 command injection vulnerability (CWE-74/CWE-77) in Tenda CH22 router firmware 1.0.0.1, reachable through a /goform/ web endpoint via an unsanitized MAC-address parameter.
Is CVE-2026-5153 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated September 1, 2026. That report is single-sourced; CISA has not listed this CVE in its own Known Exploited Vulnerabilities catalog as of our current ingestion, and we have no independent corroboration.
Do I need an account to exploit this?
NVD’s CVSS vector indicates low privileges are required (PR:L), meaning some existing, low-level access to the router’s management interface is necessary — though NVD also states the attack can be launched remotely.
Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.
Which version fixes this? Our source data does not carry a fixed-version field. Consult Tenda’s own site for firmware update availability for the CH22 model.
Severity, vector, weakness classification, and the described mechanism sourced from the National Vulnerability Database record for CVE-2026-5153, corroborated by VulDB’s catalog entry. Exploitation status and the September 1, 2026 catalog date reported by VulnCheck KEV. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our current ingestion. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.