Command Injection Flaw in Tenda AC18 Router by Tenda
CVE-2026-31255

5.4MEDIUM

Key Information:

Vendor

Tenda

Vendor
CVE Published:
27 April 2026

What is CVE-2026-31255?

A command injection flaw has been identified in the Tenda AC18 router's firmware version V15.03.05.05_multi. This vulnerability occurs within the /goform/SetSambaCfg interface, where the guestuser parameter is improperly handled. Attackers exploiting this flaw can execute arbitrary system commands, potentially compromising the integrity and security of the affected device and network.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.