CVE-2026-82695
largeMissing Authentication in Tenda AC18 Telnet Handler (CVE-2026-82695)
CVE-2026-82695 is a missing-authentication flaw (CWE-287/CWE-306) in the Telnet handler of Tenda's AC18 router, reachable via the /goform/telnet endpoint on firmware 15.03.05.19. An attacker can trigger it by simply sending requests to this endpoint from the network, as the affected function performs no authentication check. Successful exploitation grants an unauthenticated remote attacker access to the Telnet interface, and the CVSS 4.0 vector (network attack vector, no privileges required, high impact on confidentiality, integrity and availability) indicates potential full compromise of the device. Owners and administrators of Tenda AC18 routers running the affected firmware are exposed, with no other version ranges specified in the available data. A public exploit has been released and may already be used in attacks, although the issue is not yet in CISA's KEV and EPSS estimates roughly a 0.7% chance of exploitation in the next 30 days.
What to do: Check Tenda's official support/download site for updated AC18 firmware addressing the Telnet handler, since the data confirms 15.03.05.19 as affected but does not name a fixed release. As interim mitigation, disable the Telnet service, restrict router management access to the LAN only, and disable WAN-side remote management so /goform/telnet is not reachable from the internet. Check device logs for unexpected Telnet sessions or connections from unknown source addresses, given that a public exploit is already available.
| Tenda AC18 | 15.03.05.19 (firmware explicitly listed as affected; other version ranges not specified in the available data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A security flaw has been discovered in Tenda AC18 15.03.05.19. Impacted is an unknown function of the file /goform/telnet of the component Telnet Handler. The manipulation results in missing authentication. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
- Weakness
- CWE-287, CWE-306
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.