<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>AC18 (15.03.05.19) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/ac18-15.03.05.19/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 31 Aug 2026 13:58:51 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/ac18-15.03.05.19/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Critical Authentication Bypass in Tenda AC18 Telnet Handler</title><link>https://feed.craftedsignal.io/briefs/2026-08-tenda-telnet-bypass/</link><pubDate>Mon, 31 Aug 2026 13:58:51 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-tenda-telnet-bypass/</guid><description>A critical authentication bypass vulnerability in the Tenda AC18 router allows remote, unauthenticated attackers to gain unauthorized access via the Telnet service.</description><content:encoded><![CDATA[<p>CVE-2026-82695 identifies a critical security flaw in Tenda AC18 firmware version 15.03.05.19, residing in the Telnet Handler component. Specifically, the function located at /goform/telnet fails to perform proper authentication, permitting remote, unauthenticated actors to access the device's Telnet interface. This vulnerability is remotely exploitable and has been publicly disclosed with functional exploit code, posing a significant risk of device compromise. As the device provides management services, successful exploitation allows attackers to gain full administrative control over the network gateway, potentially enabling traffic interception, lateral movement, or use of the router as a botnet node. Defenders should assume that adversaries may use this as an initial access vector for further compromise of connected local networks.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability results in full administrative access to the Tenda AC18 device. This exposure impacts the confidentiality, integrity, and availability of all traffic routed through the affected device. Public availability of exploit code increases the likelihood of opportunistic scanning and mass-exploitation attempts by automated botnets targeting consumer and small-office network hardware.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Immediately restrict access to the Tenda AC18 web management and Telnet interfaces to trusted management subnets only.</li>
<li>Monitor firewall logs for unauthorized connection attempts to port 23 (Telnet) on Tenda devices.</li>
<li>Search for firmware updates from the vendor; if no patch is available, replace the device or isolate it from public-facing segments.</li>
<li>Implement network-level segmentation to prevent the Tenda device from reaching internal critical assets.</li>
</ol>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>critical-infrastructure</category><category>network-security</category><category>authentication-bypass</category></item></channel></rss>