📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global insider Education HIGH 4h Global supply_chain Software Development and Technology HIGH 9h Global apt Government/Critical Infrastructure CRITICAL 11h Global vulnerability Enterprise Software / Data Analytics CRITICAL 12h Global vulnerability Artificial Intelligence and Technology HIGH 15h Global general Technology and Artificial Intelligence MEDIUM 19h Global general Technology and Artificial Intelligence HIGH 20h Global vulnerability Higher Education CRITICAL 1d Global data_breach Government HIGH 1d Global supply_chain Software Development and Open Source Communities CRITICAL 1d Global insider Education HIGH 4h Global supply_chain Software Development and Technology HIGH 9h Global apt Government/Critical Infrastructure CRITICAL 11h Global vulnerability Enterprise Software / Data Analytics CRITICAL 12h Global vulnerability Artificial Intelligence and Technology HIGH 15h Global general Technology and Artificial Intelligence MEDIUM 19h Global general Technology and Artificial Intelligence HIGH 20h Global vulnerability Higher Education CRITICAL 1d Global data_breach Government HIGH 1d Global supply_chain Software Development and Open Source Communities CRITICAL 1d Global insider Education HIGH 4h Global supply_chain Software Development and Technology HIGH 9h Global apt Government/Critical Infrastructure CRITICAL 11h Global vulnerability Enterprise Software / Data Analytics CRITICAL 12h Global vulnerability Artificial Intelligence and Technology HIGH 15h Global general Technology and Artificial Intelligence MEDIUM 19h Global general Technology and Artificial Intelligence HIGH 20h Global vulnerability Higher Education CRITICAL 1d Global data_breach Government HIGH 1d Global supply_chain Software Development and Open Source Communities CRITICAL 1d
Vulnerabilities

CVE-2026-5152

High ⚡ Exploit Available
A vulnerability was detected in Tenda CH22 1.0.0.1. Impacted is the function formCreateFileName of the file /goform/createFileName. Performing a manipulation of the argument fileNameMit results in sta
CWE-119 — Weakness Type
Published: Mar 30, 2026  ·  Modified: Apr 6, 2026  ·  Source: NVD
CVSS v3
8.8
🔗 NVD Official
📄 Description (English)

A vulnerability was detected in Tenda CH22 1.0.0.1. Impacted is the function formCreateFileName of the file /goform/createFileName. Performing a manipulation of the argument fileNameMit results in stack-based buffer overflow. The attack may be initiated remotely. The exploit is now public and may be used.

🤖 AI Executive Summary

A critical stack-based buffer overflow vulnerability exists in Tenda CH22 firmware version 1.0.0.1 affecting the formCreateFileName function. The vulnerability can be exploited remotely without authentication through the fileNameMit parameter, allowing attackers to execute arbitrary code. With public exploits available and no patch currently released, this poses an immediate threat to organizations using affected Tenda networking equipment.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: Apr 23, 2026 16:03
🇸🇦 Saudi Arabia Impact Assessment
This vulnerability poses significant risk to Saudi organizations across multiple sectors: Telecommunications (STC, Mobily, Zain) using Tenda equipment for network infrastructure; Government agencies and NCA utilizing these devices for network management; Banking sector (SAMA-regulated institutions) relying on Tenda routers/switches for network segmentation; Healthcare facilities using Tenda equipment for medical device connectivity; Energy sector (ARAMCO and utilities) employing these devices in operational technology networks. The remote exploitability without authentication makes this particularly dangerous for organizations with internet-facing Tenda devices.
🏢 Affected Saudi Sectors
Telecommunications Government Banking Healthcare Energy Education Retail
⚖️ Saudi Risk Score (AI)
8.9
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Identify all Tenda CH22 devices running firmware 1.0.0.1 in your network using network scanning tools
2. Isolate affected devices from internet-facing networks immediately
3. Restrict access to the /goform/createFileName endpoint using firewall rules
4. Monitor for exploitation attempts using IDS/IPS signatures

PATCHING GUIDANCE:
1. Check Tenda's official website daily for firmware updates
2. When patch becomes available, test in isolated environment before production deployment
3. Maintain inventory of all Tenda devices for coordinated patching

COMPENSATING CONTROLS (until patch available):
1. Implement network segmentation to isolate Tenda devices
2. Deploy WAF rules to block requests to /goform/createFileName with suspicious fileNameMit parameters
3. Restrict administrative access to Tenda devices to trusted IP ranges only
4. Disable remote management features if not required
5. Monitor device logs for unusual file creation activities

DETECTION RULES:
1. Alert on HTTP POST requests to /goform/createFileName with fileNameMit parameter containing special characters or exceeding 256 bytes
2. Monitor for unexpected process execution from Tenda device processes
3. Track failed authentication attempts to device management interfaces
4. Alert on abnormal network traffic patterns from affected devices
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. تحديد جميع أجهزة Tenda CH22 التي تعمل بالإصدار 1.0.0.1 في شبكتك باستخدام أدوات المسح
2. عزل الأجهزة المتأثرة عن الشبكات المتصلة بالإنترنت فوراً
3. تقييد الوصول إلى نقطة النهاية /goform/createFileName باستخدام قواعد جدار الحماية
4. مراقبة محاولات الاستغلال باستخدام توقيعات IDS/IPS

إرشادات التصحيح:
1. التحقق من موقع Tenda الرسمي يومياً للحصول على تحديثات البرنامج الثابت
2. عند توفر التصحيح، اختبره في بيئة معزولة قبل نشره في الإنتاج
3. الحفاظ على جرد لجميع أجهزة Tenda لتنسيق التصحيح

الضوابط البديلة (حتى توفر التصحيح):
1. تنفيذ تقسيم الشبكة لعزل أجهزة Tenda
2. نشر قواعد WAF لحظر الطلبات إلى /goform/createFileName مع معاملات fileNameMit المريبة
3. تقييد الوصول الإداري إلى أجهزة Tenda على نطاقات IP موثوقة فقط
4. تعطيل ميزات الإدارة البعيدة إذا لم تكن مطلوبة
5. مراقبة سجلات الجهاز للأنشطة غير العادية لإنشاء الملفات

قواعد الكشف:
1. تنبيه على طلبات HTTP POST إلى /goform/createFileName مع معامل fileNameMit يحتوي على أحرف خاصة أو يتجاوز 256 بايت
2. مراقبة تنفيذ العمليات غير المتوقعة من عمليات جهاز Tenda
3. تتبع محاولات المصادقة الفاشلة لواجهات إدارة الجهاز
4. تنبيه على أنماط حركة الشبكة غير الطبيعية من الأجهزة المتأثرة
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.12.6.1 - Management of technical vulnerabilities ECC 2024 A.14.2.1 - Secure development policy ECC 2024 A.12.2.1 - Monitoring and logging of access ECC 2024 A.13.1.3 - Segregation of networks
🔵 SAMA CSF
ID.RA-1 - Asset management and vulnerability identification PR.IP-12 - Software, firmware, and information integrity mechanisms DE.CM-1 - The network is monitored to detect potential cybersecurity events RS.MI-1 - Incidents are contained
🟡 ISO 27001:2022
A.12.2.1 - Monitoring and logging of access to information and information processing facilities A.12.6.1 - Management of technical vulnerabilities A.13.1.3 - Segregation of networks A.14.2.1 - Secure development policy and procedures
🟣 PCI DSS v4.0.1
Requirement 6.2 - Ensure security patches are installed within defined timeframe Requirement 11.2 - Run automated vulnerability scans regularly
📦 Affected Products / CPE 1 entries
tenda:ch22_firmware:1.0.0.1
📊 CVSS Score
8.8
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredL — Low / Local
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityH — High
IntegrityH — High
AvailabilityH — High
📋 Quick Facts
Severity High
CVSS Score8.8
CWECWE-119
EPSS0.08%
Exploit ✓ Yes
Patch ✗ No
Published 2026-03-30
Source Feed nvd
Views 4
🇸🇦 Saudi Risk Score
8.9
/ 10.0 — Saudi Risk
Priority: CRITICAL
🏷️ Tags
exploit-available CWE-119
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.