Vulnerability Description
A vulnerability was detected in Tenda CH22 1.0.0.6(468). This issue affects the function R7WebsSecurityHandlerfunction of the component httpd. The manipulation results in path traversal. The attack may be launched remotely. The exploit is now public and may be used.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tenda | Ch22 Firmware | 1.0.0.6\(468\) |
| Tenda | Ch22 | - |
Related Weaknesses (CWE)
References
- https://github.com/Litengzheng/vuldb_new/blob/main/CH22/vul_55/README.mdExploitThird Party Advisory
- https://vuldb.com/submit/791277Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/356515Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/356515/ctiPermissions RequiredVDB Entry
- https://www.tenda.com.cn/Product
FAQ
What is CVE-2026-5962?
CVE-2026-5962 is a vulnerability with a CVSS score of 7.3 (HIGH). A vulnerability was detected in Tenda CH22 1.0.0.6(468). This issue affects the function R7WebsSecurityHandlerfunction of the component httpd. The manipulation results in path traversal. The attack ma...
How severe is CVE-2026-5962?
CVE-2026-5962 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-5962?
Check the references section above for vendor advisories and patch information. Affected products include: Tenda Ch22 Firmware, Tenda Ch22.