Impact
The vulnerability resides in the /goform/telnet endpoint of Tenda W20E firmware V16.01.0.6(2782). An unauthenticated attacker can send a request to this endpoint, causing the router to activate its Telnet daemon. Once the daemon is running, the attacker can connect to it and obtain a root shell, granting full administrative control. This flaw therefore permits remote code execution with root privileges, presenting a severe risk to confidentiality, integrity, and availability. The likely attack vector is via an HTTP request to the web interface, because the endpoint is accessed through a URI pattern commonly used by web-based management interfaces.
Affected Systems
Affected systems are routers running the Tenda W20E model with firmware version V16.01.0.6(2782). All installations of this firmware that expose the /goform/telnet endpoint are considered vulnerable, as no alternate firmware version was mentioned.
Risk and Exploitability
The CVSS score is 9.8, and the EPSS score is <1%; the vulnerability is not listed in the CISA KEV catalog. It is probable that an attacker who can reach the router’s HTTP interface (most often the LAN interface) can trigger the flaw with a single request, immediately gaining full control of the device. Consequently, the risk is severe, especially for deployments that expose the management interface to untrusted networks.
OpenCVE Enrichment