CVE-2026-24435

CWE-9423 documents3 sources
Severity
7.1HIGH
EPSS
0.0%
top 85.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 26

Description

Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) implement an insecure Cross-Origin Resource Sharing (CORS) policy on authenticated administrative endpoints. The device sets Access-Control-Allow-Origin: * in combination with Access-Control-Allow-Credentials: true, allowing attacker-controlled origins to issue credentialed cross-origin requests.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Affected Packages2 packages

NVDtenda/w30e_firmware16.01.0.19\(5037\)

🔴Vulnerability Details

2
GHSA
GHSA-9423-9282-jq44: Shenzhen Tenda W30E V2 firmware versions up to and including V162026-01-26
CVEList
Tenda W30E V2 Permissive CORS Allows Cross-origin Data Access2026-01-26
CVE-2026-24435 (HIGH CVSS 7.1) | Shenzhen Tenda W30E V2 firmware ver | cvebase.io