External risk intelligence

Tenda AC18 Telnet Missing Authentication Remote Exploit

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-82695

The vulnerability affects a Tenda wireless router, a device typically deployed at the internet edge. The Telnet handler functionality is directly reachable via the network, and such consumer routing equipment is designed to interface between the public internet and local networks.

Authentication Bypass

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A security flaw has been identified in Tenda network devices, specifically within the Telnet handler component. This vulnerability allows for remote exploitation without requiring any authentication, and a public exploit is available, increasing the potential for its misuse. The primary concern is to confirm if this specific technology is in use and assess any potential exposure.

  • Unauthenticated remote access to devices.
  • Confirms if Tenda devices are in use.
  • Assess relevance and potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker can remotely access the device's Telnet interface without needing any credentials. By exploiting a flaw within the Telnet Handler component, specifically in the `/goform/telnet` file, an attacker can bypass authentication. This vulnerability could potentially allow an attacker to gain significant control over the device and its network.

  • No authentication required for access.
  • Vulnerability triggered via `/goform/telnet`.
  • Risk of unauthorized access and control.

Live Threat

Current exploitation, exposure, and threat context

A remote, unauthenticated attacker could compromise the Tenda AC18 router's Telnet functionality due to a missing authentication flaw. This could allow for unauthorized access and manipulation of the device when it is accessible from the network.

  • Router configuration and control
  • Missing authentication allows remote access
  • Potential device takeover and misuse

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in Tenda's Telnet Handler component requires immediate attention from infrastructure and network security teams responsible for managing edge devices. The first practical step is to identify all instances of the affected Tenda AC18 devices, determine their exposure to the internet, and confirm their criticality to business operations. Once identified, the accountable owner must be engaged to plan and execute remediation based on the assessed risk.

  • Infrastructure and network teams own this.
  • Verify external reachability and business criticality.
  • Plan and coordinate immediate risk reduction.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Tenda AC18 and why does it have a Telnet Handler?

The Tenda AC18 is a wireless router designed to manage network traffic for homes and small offices. It acts as a gateway between your local devices and the internet. The Telnet Handler is a component within the router's software intended to allow administrators to remotely log in and manage device settings via a command-line interface, typically for troubleshooting or configuration purposes.

What is the vulnerability in CVE-2026-82695?

This flaw is classified as a missing authentication vulnerability (CWE-306). In simple terms, the router's software fails to verify the identity of someone trying to access its management functions. Because of this oversight, an attacker can bypass the login process entirely and gain unauthorized control over the device without needing a username or password.

How is the CVE-2026-82695 vulnerability triggered?

The issue is triggered by interacting with a specific file on the router, located at /goform/telnet. By sending a request to this path, an attacker can exploit the missing authentication logic. Importantly, this does not require an attacker to have prior access to the internal network; the bug is reachable remotely, meaning the device can be compromised by anyone who can reach it over the network.

Why should I care about this if my router is internal?

Halo Surface Signal indicates that Tenda routers are often deployed at the internet edge, making them highly reachable. If your device is directly connected to the public internet, it faces the highest risk because anyone can reach the vulnerable Telnet handler. If your device is strictly internal, the risk is lower, but it remains a critical concern if the router is misconfigured to allow wide access.

What should I do if I use a Tenda AC18?

First, identify if any Tenda AC18 routers are currently active in your infrastructure. Determine if these devices are directly exposed to the internet. If you find affected units, treat them as a high priority for review. Coordinate with your network team to restrict access to the device management interfaces and immediately investigate the manufacturer's support channels for guidance on securing or updating the affected software.

References