Critical Authentication Bypass in Tenda AC18 Telnet Handler
A critical authentication bypass vulnerability in the Tenda AC18 router allows remote, unauthenticated attackers to gain unauthorized access via the Telnet service.
CVE search metadata
CVE search record: CVE-2026-82695. Severity: critical. CVSS: 10.0. KEV: no. Product: AC18 (15.03.05.19). Brief: Critical Authentication Bypass in Tenda AC18 Telnet Handler. Brief link: https://feed.craftedsignal.io/briefs/2026-08-tenda-telnet-bypass/
CVE-2026-82695 identifies a critical security flaw in Tenda AC18 firmware version 15.03.05.19, residing in the Telnet Handler component. Specifically, the function located at /goform/telnet fails to perform proper authentication, permitting remote, unauthenticated actors to access the device's Telnet interface. This vulnerability is remotely exploitable and has been publicly disclosed with functional exploit code, posing a significant risk of device compromise. As the device provides management services, successful exploitation allows attackers to gain full administrative control over the network gateway, potentially enabling traffic interception, lateral movement, or use of the router as a botnet node. Defenders should assume that adversaries may use this as an initial access vector for further compromise of connected local networks.
Impact
Successful exploitation of this vulnerability results in full administrative access to the Tenda AC18 device. This exposure impacts the confidentiality, integrity, and availability of all traffic routed through the affected device. Public availability of exploit code increases the likelihood of opportunistic scanning and mass-exploitation attempts by automated botnets targeting consumer and small-office network hardware.
Recommendation
- Immediately restrict access to the Tenda AC18 web management and Telnet interfaces to trusted management subnets only.
- Monitor firewall logs for unauthorized connection attempts to port 23 (Telnet) on Tenda devices.
- Search for firmware updates from the vendor; if no patch is available, replace the device or isolate it from public-facing segments.
- Implement network-level segmentation to prevent the Tenda device from reaching internal critical assets.
Immediate actions
Restrict inbound Telnet access to Tenda devices via network edge firewall
Threat Hunt
Identify Tenda AC18 devices communicating on port 23 from external IP addresses
Data: Firewall logs, Netflow
Mitigations
Disable Telnet service on Tenda AC18 if not required
CVE-2026-82695