CVE-2026-31255: Command Injection
A command injection vulnerability exists in Tenda AC18 V15.03.05.05multi. The vulnerability is located in the /goform/SetSambaCfg interface, where improper handling of the guestuser parameter allows attackers to execute arbitrary system commands.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-31255?
CVE-2026-31255 is categorized as a critical command injection vulnerability that can allow attackers to execute arbitrary system commands.
How do I fix CVE-2026-31255?
To fix CVE-2026-31255, it is recommended to update the Tenda AC18 device to a non-vulnerable firmware version.
Which devices are affected by CVE-2026-31255?
CVE-2026-31255 affects the Tenda AC18 router specifically running firmware version V15.03.05.05_multi.
What kind of attacks can leverage CVE-2026-31255?
An attacker can exploit CVE-2026-31255 to gain unauthorized command execution on the Tenda AC18 device.
Is it safe to use Tenda AC18 with CVE-2026-31255?
Using Tenda AC18 with the vulnerable firmware version poses significant security risks and should be addressed immediately.