Sceawere

Vulnerability Detail

CVE-2026-67966UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Tenda W20E Unauthenticated Telnet Activation

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
21h ago
Vendor
n/a
Product
n/a
Attack Type
n/a
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Tenda W20E V16.01.0.6(2782) /goform/telnet endpoint allows unauthenticated remote attackers to activate the Telnet daemon and obtain root shell access.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-08-17T21:16:47.737Z",
  "pubdate": "2026-08-17T21:16:47.737Z",
  "executiveSummary": "An unauthenticated remote command execution and service activation vulnerability exists within the Tenda W20E V16.01.0.6(2782) firmware. The vulnerability resides in the /goform/telnet endpoint, which improperly permits unauthenticated external actors to interact with the device and forcefully initialize the underlying Telnet daemon.\nSuccessful exploitation of this flaw grants attackers complete, unrestricted root shell access to the targeted network device without requiring prior authentication credentials or interaction from a legitimate administrator.\nThe affected product is the Tenda W20E router running version V16.01.0.6(2782). The risk implications are severe, as unauthorized administrative access to a core network routing device allows malicious entities to intercept traffic, modify firewall rules, pivot deeper into internal network segments, or permanently disable the hardware via firmware corruption.\nAttacker capabilities include full system compromise at the highest privilege level (root). Exploitation requirements are minimal, necessitating only network connectivity to the vulnerable endpoint exposed by the router, typically via the local network or wide-area network if management interfaces are misconfigured and exposed.",
  "technicalDetails": "The vulnerability stems from improper access control and inadequate input validation within the web management interface of the Tenda W20E V16.01.0.6(2782) firmware. Specifically, the vulnerable component is the HTTP handler associated with the /goform/telnet endpoint.\nThe root cause of the issue is the lack of session validation, authentication checks, or authorization enforcement prior to executing internal system commands. When a remote HTTP request is sent to the /goform/telnet URI, the backend application logic processes the request and directly invokes system-level routines designed to start the Telnet daemon service (telnetd).\nThe attack flow proceeds as follows: An unauthenticated attacker crafts an HTTP request targeting the /goform/telnet endpoint on the router's web server. Upon receiving this request, the vulnerable endpoint fails to verify if the incoming connection originates from an authenticated session belonging to a legitimate administrator. Instead, the application trusts the input unconditionally and triggers the system initialization scripts to launch the Telnet service on its standard listening port.\nOnce the Telnet daemon is active, the attacker can establish a direct TCP connection to the device's Telnet port. Due to insecure default configurations or hardcoded administrative pathways exposed by the daemon initialization routine, the attacker is immediately granted a root shell interface.\nThe privilege level achieved post-exploitation is absolute root access, allowing the execution of arbitrary system binaries, inspection of sensitive configuration files containing plaintext credentials, manipulation of routing tables, and installation of persistent backdoors. The vulnerability is accessible over the network protocol stack, specifically targeting the HTTP/HTTPS management service exposed by the device. No privileges or credentials are required to initiate the attack flow."
}
CVE-2026-67966: Tenda W20E Unauthenticated Telnet Activation (CRITICAL Severity, CVSS: 9.8) - Sceawere