cbcvebase.
CVE-2024-46430
published 2025-02-10

CVE-2024-46430: Tenda W18E V16.01.0.8(1625) is vulnerable to Incorrect Access Control. Unauthorized password change via the web management portal allows an unauthenticated…

PriorityP336medium6.5CVSS 3.1
AVAACLPRNUINSUCNIHAN
EPSS
0.82%
52.9th percentile
Tenda W18E V16.01.0.8(1625) is vulnerable to Incorrect Access Control. Unauthorized password change via the web management portal allows an unauthenticated remote attacker to change the administrator password by sending a specially crafted HTTP POST request to the setLoginPassword function, bypassing the authentication mechanism.

Affected

1 ranges
VendorProductVersion rangeFixed in
tendaw18e_firmware
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.