What is CVE-2026-67966?
CVE-2026-67966: In Tenda W20E router version V16.01.0.6(2782), the `/goform/telnet` endpoint allows an unauthenticated remote attacker to activate the Telnet daemon and gain root shell access. Affected devices should be isolated from the network, and remote management interfaces should be disabled until a security update is provided by the vendor.
Azərbaycanca: CVE-2026-67966: Tenda W20E routerinin V16.01.0.6(2782) versiyasında `/goform/telnet` endpoint-i autentifikasiya olunmamış uzaqdan hücumçuya Telnet xidmətini aktivləşdirməyə və root shell əldə etməyə imkan verir. Təsirlənən cihazları şəbəkədən təcrid etmək və istehsalçı tərəfindən təhlükəsizlik yeniləməsi yayımlanana qədər uzaqdan idarəetmə interfeyslərini söndürmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
Which device is affected by CVE-2026-67966?
This vulnerability affects the Tenda W20E router version V16.01.0.6(2782).
What can an attacker gain through CVE-2026-67966?
An unauthenticated remote attacker can activate the Telnet daemon via the `/goform/telnet` endpoint and gain root shell access.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.