Tenda AC18 Telnet Handler Missing Authentication Vulnerability (CVE-2026-82695)

Release Date: 31st August 2026 (Added 9 September 2026)

Impact : CRITICAL

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations, System/Network administrators, and members of the general public that use a Tenda AC18 wireless router. This alert is intended to be understood by both technical and general readers.

What is it?

CVE-2026-82695 is a missing-authentication vulnerability in the Telnet Handler component of the Tenda AC18, a mass-market AC1900-class dual-band Wi-Fi router sold through general electronics retailers worldwide (Amazon, eBay, and other consumer retail channels), with no dependency on any specific ISP.

Reference

  1. https://www.cve.org/CVERecord?id=CVE-2026-82695
  2. https://cve.threatint.com/CVE/CVE-2026-82695