Tenda AC18 Command Injection Vulnerability in Samba Configuration Interface

Vulnerability

A command injection vulnerability has been identified in the Tenda AC18 router, specifically in the V15.03.05.05_multi firmware. The issue arises in the /goform/SetSambaCfg interface, where improper handling of the guestuser parameter enables attackers to execute arbitrary system commands. Exploitation of this vulnerability could lead to a complete compromise of the affected device.

Impact

Successful exploitation allows authenticated attackers to execute arbitrary system commands on the router, potentially leading to full device compromise.

Reproduction

To reproduce this vulnerability, an authenticated attacker must send a POST request to the /goform/SetSambaCfg endpoint. The request must include malicious payloads in the guestuser parameter, such as shell metacharacters that can be used to execute commands. Once the payload is injected and the request is processed, the injected command will be executed during a subsequent request, demonstrating the command injection vulnerability.

Added: Apr 27, 2026, 7:22 PM
Updated: Apr 27, 2026, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
7.5
exploitability
6.2
remediation
7.7
relevance
6.8
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.