Executive brief
A security vulnerability has been identified in the Tenda AC18 router, a device used to provide wireless internet access. An unauthorized person could remotely send a specially crafted request to the router to take control of the device. This could allow an attacker to disrupt internet service or potentially monitor network traffic.
Technical details
A command injection vulnerability (CWE-77) exists in the Tenda AC18 router running firmware version v15.03.05.05. The flaw is located within the '/goform/fast_setting_internet_set' endpoint, which fails to properly sanitize the 'mac' input parameter. An unauthenticated remote attacker can exploit this by sending a malicious HTTP request containing shell metacharacters in the MAC address field. Successful exploitation allows for arbitrary OS command execution on the underlying system. The vulnerability is described as second-order in some documentation, suggesting the injected payload may be stored and executed during a subsequent process.
Affected products
- Tenda AC18 v15.03.05.05
Timeline
- 2026-07-01: advisory: CVE-2026-38142 published by NVD