Impact
A flaw in Tenda AC18 firmware version 15.03.05.19 allows remote attackers to exploit the Telnet Handler's /goform/telnet endpoint without authentication. The missing authentication check enables an attacker to gain control of the device, potentially executing arbitrary commands or commands that affect network traffic. The vulnerability is classified with a CVSS score of 10, indicating a high severity and full impact on confidentiality, integrity, and availability from a single compromised host.
Affected Systems
Vulnerable devices are Tenda AC18 routers running firmware 15.03.05.19. No other vendors or product lines are listed as affected in the available data.
Risk and Exploitability
The attack vector is remote, leveraging the Telnet interface exposed by the router. An exploit is publicly available, and the lack of authentication permits immediate remote code execution if the device is reachable over the network. The EPSS score is not supplied, but the existence of a static public exploit and the CVSS v10 score signals a high likelihood of exploitation in practice. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment