CVE-2026-24440

CWE-6203 documents3 sources
Severity
8.7HIGH
EPSS
0.1%
top 81.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 26

Description

Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) allow account passwords to be changed through the maintenance interface without requiring verification of the existing password. This enables unauthorized password changes when access to the affected endpoint is obtained.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Packages2 packages

NVDtenda/w30e_firmware16.01.0.19\(5037\)

🔴Vulnerability Details

2
CVEList
Tenda W30E V2 Allows Password Changes Without Verifying Current Password2026-01-26
GHSA
GHSA-46gc-wc69-mw4h: Shenzhen Tenda W30E V2 firmware versions up to and including V162026-01-26
CVE-2026-24440 (HIGH CVSS 8.7) | Shenzhen Tenda W30E V2 firmware ver | cvebase.io