← Terug naar overzicht

A security vulnerability has been identified in Tenda AC18 firmware version 15.03.05.19. The flaw resides in an unknown function within the /goform/telnet endpoint of the Telnet Handler component. The vulnerability stems from missing authentication controls, allowing unauthenticated remote attackers to interact with the telnet interface. The attack can be launched remotely without requiring any credentials or local access. A public exploit has already been released, increasing the risk of active exploitation in the wild. The affected product is a widely used consumer and small business wireless router. The vulnerability is tracked as CVE-2026-82695 and has been published on NVD and VulnDB. Organizations and individuals using Tenda AC18 routers should apply mitigations or patches as soon as they become available.

Affected products

  • Tenda AC18 15.03.05.19

Related CVE's

  • CVE-2026-82695

Categories

  • Identity & Access
  • Mobile & IoT
  • Network Infrastructure
  • Zero-Day Vulnerabilities