CVE-2026-82695: Tenda AC18 Telnet telnet missing authentication
A security flaw has been discovered in Tenda AC18 15.03.05.19. Impacted is an unknown function of the file /goform/telnet of the component Telnet Handler. The manipulation results in missing authentication. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Tenda AC18to a version that resolves this vulnerability.Fixed in 15.03.05.19 - Compensating control
Because Telnet missing authentication can be exploited remotely via /goform/telnet (Telnet Handler), restrict network access to the device’s Telnet functionality (e.g., block Telnet at the firewall/ACL) until the Telnet authentication issue is remediated.
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker can launch the attack remotely and does not need authentication or user interaction. Public exploit availability increases the likelihood of attempted exploitation.
Which product version is identified as affected?
The reported affected version is Tenda AC18 15.03.05.19, specifically the Telnet Handler endpoint at /goform/telnet.
What security impact can exploitation have?
The provided severity vector indicates high impact to confidentiality, integrity, and availability, with scope changed.