A vulnerability categorized as very critical has been discovered in Tenda W20E 16.01.0.6. Affected is the function url_need_login. The manipulation results in code injection.

This vulnerability is cataloged as CVE-2026-67965. The attack may be launched remotely. There is no exploit available.