Sceawere

Vulnerability Detail

CVE-2026-82695UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Tenda AC18 Telnet Authentication Bypass

Vulnerability Metadata

Severity
Critical
Score / CVSS
10
Creation Date
17h ago
Vendor
Tenda
Product
AC18
Attack Type
Missing Authentication
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A security flaw has been discovered in Tenda AC18 15.03.05.19. Impacted is an unknown function of the file /goform/telnet of the component Telnet Handler. The manipulation results in missing authentication. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "10.0",
  "pubDate": "2026-08-31T13:18:29.953Z",
  "pubdate": "2026-08-31T13:18:29.953Z",
  "executiveSummary": "A critical security vulnerability has been identified in Tenda AC18 firmware version 15.03.05.19, specifically involving the /goform/telnet handler.\nThe vulnerability is classified as an authentication bypass, allowing unauthenticated remote attackers to interact with restricted system services.\nBy manipulating the Telnet Handler component, an attacker can circumvent standard access control mechanisms, potentially gaining unauthorized administrative access to the underlying operating system.\nThe flaw is exacerbated by the availability of public exploit code, increasing the likelihood of automated or targeted exploitation attempts.\nGiven that the device is a network router, successful exploitation poses significant risk, including potential network traffic interception, unauthorized configuration changes, and total system compromise.\nAs this vulnerability allows remote execution without prior authentication, it is considered a high-risk entry point for adversaries targeting the local network environment.",
  "technicalDetails": "The vulnerability resides within the /goform/telnet handler of the Tenda AC18 router running firmware 15.03.05.19. The root cause is a failure in the application's authentication logic, which fails to verify the requestor's identity before processing requests directed to the Telnet service configuration.\nThe Telnet Handler is responsible for managing the state and accessibility of the Telnet daemon on the device. In the affected firmware, the HTTP handler associated with /goform/telnet does not enforce session validation or credential verification. Consequently, a remote attacker can transmit a specifically crafted HTTP request to this endpoint to toggle or enable Telnet access without providing valid administrative credentials.\nThe attack flow begins with the attacker identifying the target device's management interface. The attacker then sends an HTTP POST request to the /goform/telnet URI. By manipulating the request parameters, the attacker forces the Telnet Handler to modify the device's configuration, enabling the Telnet service on the system. Once enabled, the Telnet service typically binds to a network-facing port, allowing the attacker to establish a raw socket connection.\nBecause the system lacks robust authentication gates for this specific CGI-based request, the handler fails to sanitize or validate the authorization state of the client. The payload is simple, involving standard HTTP interactions that trigger server-side side effects. Post-exploitation, an attacker can access the router via the Telnet protocol using default or subsequently modified credentials, resulting in full shell access to the underlying Linux-based firmware.\nOnce the attacker gains shell-level privileges, they can execute arbitrary system commands, pivot deeper into the internal network, modify firewall rules, or establish persistence. This vulnerability exposes the router to remote management compromise, effectively nullifying the security boundary between the WAN/LAN interfaces and the router's internal system processes.\nThe requirement for exploitation is minimal: the attacker simply needs network connectivity to the device's management interface. Since the /goform/telnet file is accessible remotely, the attack surface is exposed to any network segment with a route to the device, making it highly susceptible to scanning and automated exploitation scripts."
}
CVE-2026-82695: Tenda AC18 Telnet Authentication Bypass (CRITICAL Severity, CVSS: 10.0) - Sceawere