Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-67966: Tenda W20E Telnet Service Left Unsecured
CVE-2026-67966 · published 17 days ago
Summary
The Tenda W20E wireless router has a security issue where an attacker can remotely access the router without a password and gain full control. This can allow an attacker to change settings, access sensitive information, and disrupt the network. To fix this, update the router's firmware to the latest version or change the router's password and enable firewall settings to block incoming Telnet connections.
Original advisory text
Tenda W20E V16.01.0.6(2782) /goform/telnet endpoint allows unauthenticated remote attackers to activate the Telnet daemon and obtain root shell access.
Tenda W20E V16.01.0.6(2782) /goform/telnet endpoint allows unauthenticated remote attackers to activate the Telnet daemon and obtain root shell access.
Severity
9.8
Critical
Exploitation
EPSS <1%
Type
CWE-306Missing Authentication for Critical Function
Timeline
Published17 Aug 2026
Updated3 Sep 2026
First seen17 Aug 2026
Monitor software like this
Free during beta