CVE-2026-19346
A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formCertListInfo of the file /goform/CertListI
CVSS
8.8
High
EPSS
—
KEV
—
Exploit Today
0
0-100
Published: Aug 9, 2026 · Last modified: Aug 9, 2026 · CWE-74 · CWE-77
Not enough EPSS history yet.
A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formCertListInfo of the file /goform/CertListInfo. This manipulation of the argument Name causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.
- candle-throne-f75.notion.sitehttps://candle-throne-f75.notion.site/Tenda-CH22-formCertListInfo-387df0aa118580b4abfcffaf2fceb9ff
- vuldb.comhttps://vuldb.com/cve/CVE-2026-19346
- vuldb.comhttps://vuldb.com/submit/865530
- vuldb.comhttps://vuldb.com/vuln/387182
- vuldb.comhttps://vuldb.com/vuln/387182/cti
- www.tenda.com.cnhttps://www.tenda.com.cn/
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-193489.8 CRI—
——0A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. Impacted is the function sprintf of the file /protocol.csp?fname=net&opt=smacfilter_conf&function=set&act=add&name=test&enable=1. Performing a manipulation of the argument enable/name/mac results in command injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.3hCVE-2026-193476.3 MED—
——0A vulnerability was identified in itsourcecode Hospital Management System 1.0. This issue affects some unknown processing of the file /viewdoctor.php. Such manipulation of the argument delid leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.3hCVE-2026-193447.3 HIG—
——0A vulnerability has been found in code-projects Task Management System 1.0. Affected by this issue is some unknown functionality of the file /user/comment_count_user.php. The manipulation of the argument task_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.4hCVE-2026-193437.3 HIG—
——0A flaw has been found in code-projects Task Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/AdminLogin.php. Executing a manipulation of the argument email/password can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used.6hCVE-2026-193345.3 MED—
——0A flaw has been found in NightTrek Ollama-mcp up to 80cf2e17cfc144963a475b619093a2d13c13dbc9. This affects an unknown part of the file src/index.ts. This manipulation of the argument name/modelfile/source/destination causes command injection. The attack can only be executed locally. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.9hCVE-2026-193335.3 MED—
——0A vulnerability was detected in NightTrek Supabase-MCP cc994ab2d2a36b0af6ee7c7f3e6ce8e08cda2170/db03237d92f7dc2f0da0d70a87dba84ebcde5b66. Affected by this issue is some unknown functionality of the component generate_types. The manipulation of the argument schema results in command injection. The attack needs to be approached locally. The project was informed of the problem early through an issue report but has not responded yet.9h