ZeroHour

CVE-2026-82695

large

Missing Authentication in Tenda AC18 Telnet Handler (CVE-2026-82695)

CVSS 4.0
9.3 critical
EPSS
<1%p53
Published
()
Modified
AI analysis

CVE-2026-82695 is a missing-authentication flaw (CWE-287/CWE-306) in the Telnet handler of Tenda's AC18 router, reachable via the /goform/telnet endpoint on firmware 15.03.05.19. An attacker can trigger it by simply sending requests to this endpoint from the network, as the affected function performs no authentication check. Successful exploitation grants an unauthenticated remote attacker access to the Telnet interface, and the CVSS 4.0 vector (network attack vector, no privileges required, high impact on confidentiality, integrity and availability) indicates potential full compromise of the device. Owners and administrators of Tenda AC18 routers running the affected firmware are exposed, with no other version ranges specified in the available data. A public exploit has been released and may already be used in attacks, although the issue is not yet in CISA's KEV and EPSS estimates roughly a 0.7% chance of exploitation in the next 30 days.

What to do: Check Tenda's official support/download site for updated AC18 firmware addressing the Telnet handler, since the data confirms 15.03.05.19 as affected but does not name a fixed release. As interim mitigation, disable the Telnet service, restrict router management access to the LAN only, and disable WAN-side remote management so /goform/telnet is not reachable from the internet. Check device logs for unexpected Telnet sessions or connections from unknown source addresses, given that a public exploit is already available.

Affected
Tenda AC1815.03.05.19 (firmware explicitly listed as affected; other version ranges not specified in the available data)
Estimated exposure
largeRoughly hundreds of thousands of devices plausibly affected (Tenda AC18 is a widely sold consumer router, and Tenda is among the most frequently observed… — The estimate is based on the AC18's popularity as a budget home router and the large number of Tenda devices routinely observed internet-facing in public scan data, with home routers commonly exposing their web management interface…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A security flaw has been discovered in Tenda AC18 15.03.05.19. Impacted is an unknown function of the file /goform/telnet of the component Telnet Handler. The manipulation results in missing authentication. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.

Weakness
CWE-287, CWE-306
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.