Cyber & AI intelligence
Wasteland.
Briefs indexed2348
Issues26
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-82695 2026-08-31

Tenda AC18 Ships an Unauthenticated Telnet Endpoint

"The editorial note is truncated mid-string; it shows the frontmatter title only as far as `Tenda AC18 Ships an Unauthenticated Telnet Endpoint “`, so I can't reconstruct the quoted portion that follows. I've left the H1…"

The editorial note is truncated mid-string; it shows the frontmatter title only as far as Tenda AC18 Ships an Unauthenticated Telnet Endpoint “, so I can't reconstruct the quoted portion that follows. I've left the H1 as the recoverable prefix rather than invent the rest; send me the full frontmatter title and I'll align it exactly.

Tenda AC18 Ships an Unauthenticated Telnet Endpoint

A missing-authentication flaw in the Telnet handler of Tenda AC18 firmware 15.03.05.19 lets a remote attacker reach /goform/telnet with no credentials, and public exploit code is already available.

What Is It

CVE-2026-82695 is an authentication bypass in the Telnet Handler component of the Tenda AC18 router. An unknown function serving the /goform/telnet endpoint can be manipulated to produce a state of missing authentication. The issue is tracked under CWE-287 (Improper Authentication) and CWE-306 (Missing Authentication for Critical Function), and was assigned by VulDB as the CNA. It was published to NVD on 2026-08-31 and currently carries a status of "Received."

The attack is launched remotely and requires no privileges, no user interaction, and no special attack conditions. Per the NVD record, the exploit has been released to the public and may be used for attacks.

Why It Matters

The CVSS 3.1 base score is 10.0 (CRITICAL) with vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, a maximum score driven by network reachability, low complexity, no authentication, and a changed scope with high confidentiality, integrity, and availability impact. The CVSS 4.0 assessment scores 9.3 (CRITICAL) and rates exploit maturity as PROOF_OF_CONCEPT, with high impact across both the vulnerable system and subsequent systems. The legacy CVSS 2.0 vector is AV:N/AC:L/Au:N/C:C/I:C/A:C, also 10.0.

An unauthenticated telnet path on a consumer edge router is a direct route to the device and, by extension, the network behind it.

What's Vulnerable

Patch Status

The supplied source material contains no CISA KEV entry for CVE-2026-82695: there is no confirmation of active exploitation in the wild and no KEV-mandated required action or due date. No vendor patch, fixed version, or mitigation guidance is present in the NVD record. Public exploit code exists, so treat exposure of the telnet interface as the operative risk pending vendor information.

Sources