CVE-2026-67966: Tenda W20E V16.01.0.6(2782) vulnerability
Published Aug 17, 2026
·Updated
Tenda W20E V16.01.0.6(2782) /goform/telnet endpoint allows unauthenticated remote attackers to activate the Telnet daemon and obtain root shell access.
Affected Software
1 affected component
Tenda W20E V16.01.0.6(2782)=V16.01.0.6(2782)
Event History
Aug 17, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2026-67966?
CVE-2026-67966 has a risk rating of 92, indicating it is a critical vulnerability.
2
What does CVE-2026-67966 allow an attacker to do?
CVE-2026-67966 allows unauthenticated remote attackers to activate the Telnet daemon and obtain root shell access.
3
How can I protect my Tenda W20E from CVE-2026-67966?
To protect against CVE-2026-67966, ensure that the Telnet service is disabled or restrict access to trusted networks only.
4
Is a patch available for CVE-2026-67966?
As of now, there is no official patch for CVE-2026-67966, so users should take immediate steps to secure their devices.
5
What should I do if I am affected by CVE-2026-67966?
If affected by CVE-2026-67966, it is advised to disable the Telnet service and monitor the device for any unauthorized access.