CVE-2026-31255

· NIST NVD ↗

A command injection vulnerability exists in Tenda AC18 V15.03.05.05_multi. The vulnerability is located in the /goform/SetSambaCfg interface, where improper handling of the guestuser parameter allows attackers to execute arbitrary system commands.

CRITICAL
CVSS severity
9.8
CVSS base score
2026-04-27
Published

CWE codes

CWE-77CWE-77

Affected products

tenda:ac18_firmwaretenda:ac18

Sources