CVE-2026-82695
Received Received - Intake

Authentication Bypass in Tenda AC18 Router

Vulnerability report for CVE-2026-82695, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-31

Last updated on: 2026-08-31

Assigner: VulDB

Description

A security flaw has been discovered in Tenda AC18 15.03.05.19. Impacted is an unknown function of the file /goform/telnet of the component Telnet Handler. The manipulation results in missing authentication. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-31
Last Modified
2026-08-31
Generated
2026-08-31
AI Q&A
2026-08-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
tenda ac18 15.03.05.19

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a missing authentication flaw in the Tenda AC18 router firmware version 15.03.05.19. It allows remote attackers to enable Telnet access without credentials by exploiting the /goform/telnet endpoint. In default configurations, the admin password is empty, making the device vulnerable to unauthorized access.

Detection Guidance

Check if the Tenda AC18 router has Telnet enabled without authentication by sending an HTTP request to /goform/telnet. If the response indicates Telnet is enabled or if you can access the device via Telnet without credentials, the system is likely vulnerable.

Impact Analysis

This vulnerability enables remote attackers to gain unauthorized Telnet access to the router. Once exploited, attackers could execute arbitrary commands, leading to full system compromise, data theft, or further network infiltration. The public availability of exploit code increases the risk of real-world attacks.

Compliance Impact

This vulnerability likely violates compliance requirements for data protection and network security, such as GDPR and HIPAA, due to inadequate access controls and potential unauthorized access to sensitive data. Organizations using affected devices may face regulatory penalties for failing to maintain secure configurations.

Mitigation Strategies

Disable Telnet access on the Tenda AC18 router and enable strong authentication. Update the router firmware to the latest version if available. Block external access to the router's web interface and Telnet port (23) from untrusted networks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82695. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart