Description
Tenda W20E V16.01.0.6(2782) /goform/telnet endpoint allows unauthenticated remote attackers to activate the Telnet daemon and obtain root shell access.
Published: 2026-08-17
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the /goform/telnet endpoint of Tenda W20E firmware V16.01.0.6(2782). An unauthenticated attacker can send a request to this endpoint, causing the router to activate its Telnet daemon. Once the daemon is running, the attacker can connect to it and obtain a root shell, granting full administrative control. This flaw therefore permits remote code execution with root privileges, presenting a severe risk to confidentiality, integrity, and availability. The likely attack vector is via an HTTP request to the web interface, because the endpoint is accessed through a URI pattern commonly used by web-based management interfaces.

Affected Systems

Affected systems are routers running the Tenda W20E model with firmware version V16.01.0.6(2782). All installations of this firmware that expose the /goform/telnet endpoint are considered vulnerable, as no alternate firmware version was mentioned.

Risk and Exploitability

The CVSS score is 9.8, and the EPSS score is <1%; the vulnerability is not listed in the CISA KEV catalog. It is probable that an attacker who can reach the router’s HTTP interface (most often the LAN interface) can trigger the flaw with a single request, immediately gaining full control of the device. Consequently, the risk is severe, especially for deployments that expose the management interface to untrusted networks.

Generated by OpenCVE AI on August 18, 2026 at 20:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and install the latest Tenda firmware that disables the telnet activation endpoint or patches the flaw.
  • Disable the Telnet service in the router’s configuration, and block outbound connections on port 23 if the service must remain enabled.
  • Restrict access to the router’s web interface to trusted internal network segments or a VPN, preventing unauthorized remote users from reaching the /goform/telnet endpoint.

Generated by OpenCVE AI on August 18, 2026 at 20:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Activation of Telnet Grants Root Access on Tenda W20E Firmware
Weaknesses CWE-284

Tue, 18 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Activation of Telnet Grants Root Access on Tenda W20E Firmware
Weaknesses CWE-284

Mon, 17 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Description Tenda W20E V16.01.0.6(2782) /goform/telnet endpoint allows unauthenticated remote attackers to activate the Telnet daemon and obtain root shell access.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-18T15:52:41.425Z

Reserved: 2026-07-30T00:00:00.000Z

Link: CVE-2026-67966

cve-icon Vulnrichment

Updated: 2026-08-18T15:51:25.299Z

cve-icon NVD

Status : Deferred

Published: 2026-08-17T21:16:47.737

Modified: 2026-08-31T20:12:02.273

Link: CVE-2026-67966

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T21:00:04Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function