Description
A command injection vulnerability exists in Tenda AC18 V15.03.05.05_multi. The vulnerability is located in the /goform/SetSambaCfg interface, where improper handling of the guestuser parameter allows attackers to execute arbitrary system commands.
Published: 2026-04-27
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch
AI Analysis

Impact

The vulnerability originates from improper handling of the guestuser parameter in the /goform/SetSambaCfg interface, allowing command injection. This weakness can be exploited to execute arbitrary system commands, giving an attacker full control over the device. It aligns with CWE-77, and jeopardizes confidentiality, integrity, and availability.

Affected Systems

The affected product is a Tenda AC18 router running firmware version V15.03.05.05_multi. No other vendors, products, or versions are listed in the CVE record.

Risk and Exploitability

The CVSS score of 5.4 and an EPSS score of < 1% indicate a moderate vulnerability with a low but non-zero likelihood of exploitation. The likely attack vector is access to the router’s web administration interface, reachable from the local network. Because the flaw permits arbitrary command execution, the potential risk is high, especially if an attacker can reach the interface from within the network or from a compromised device. The vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on April 29, 2026 at 02:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the router firmware to a version that fixes the command injection flaw.
  • Restrict web administration access to trusted LAN subnets or the loopback interface, blocking external or unintended local access.
  • Disable the Samba guest service if it is not required for network operations.

Generated by OpenCVE AI on April 29, 2026 at 02:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Apr 2026 02:45:00 +0000

Type Values Removed Values Added
Title Command Injection in Tenda AC18 Firmware Allowing System Command Execution

Wed, 29 Apr 2026 00:00:00 +0000

Type Values Removed Values Added
Title Command Injection in Tenda AC18 Firmware Allows Remote Code Execution
Weaknesses CWE-78
CWE-94

Tue, 28 Apr 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Tue, 28 Apr 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Tenda ac18 Firmware
Weaknesses CWE-77
CPEs cpe:2.3:h:tenda:ac18:-:*:*:*:*:*:*:*
cpe:2.3:o:tenda:ac18_firmware:15.03.05.05:*:*:*:*:*:*:*
Vendors & Products Tenda ac18 Firmware
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Tue, 28 Apr 2026 13:45:00 +0000

Type Values Removed Values Added
Title Command Injection in Tenda AC18 Firmware Allows Remote Code Execution
Weaknesses CWE-78
CWE-94

Tue, 28 Apr 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Tenda
Tenda ac18
Vendors & Products Tenda
Tenda ac18

Mon, 27 Apr 2026 18:45:00 +0000

Type Values Removed Values Added
Description A command injection vulnerability exists in Tenda AC18 V15.03.05.05_multi. The vulnerability is located in the /goform/SetSambaCfg interface, where improper handling of the guestuser parameter allows attackers to execute arbitrary system commands.
References

Subscriptions

Tenda Ac18 Ac18 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-04-28T15:06:36.415Z

Reserved: 2026-03-09T00:00:00.000Z

Link: CVE-2026-31255

cve-icon Vulnrichment

Updated: 2026-04-28T15:06:31.627Z

cve-icon NVD

Status : Modified

Published: 2026-04-27T19:16:47.060

Modified: 2026-04-28T15:16:28.360

Link: CVE-2026-31255

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T02:30:07Z

Weaknesses