CVE-2026-38142EPSS p49.6%
CVE-2026-38142CVE-2026-38142
Description
An unauthenticated command injection vulnerability in the /goform/fast_setting_internet_set endpoint of Tenda AC18 v15.03.05.05 allows attackers to execute arbitrary commands via a crafted payload injected into the mac parameter.
Scoring
| CVSS | 6.5 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
| EPSS | 0.69% probability of exploitation · percentile 49.6% · 2026-08-15T12:02:44Z |
| Last modified | 2026-07-02 |