CVE-2018-5770: Tendacn AC15 Firmware
Critical severity, CVSS 9.8. EPSS: 2.7% chance of exploitation in the next 30 days.
An issue was discovered on Tenda AC15 devices. A remote, unauthenticated attacker can make a request to /goform/telnet, creating a telnetd service on the device. This service is password protected; however, several default accounts exist on the device that are root accounts, which can be used to log in.
Affected products
- Tendacn AC15 Firmware: affected versions not specified
Published 2018-03-20. Last modified 2026-06-17.