cbcvebase.

Tenda W30E Firmware vulnerabilities

63 known vulnerabilities affecting tenda/w30e_firmware.

Total CVEs
63
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL18HIGH36MEDIUM9

Vulnerabilities

Page 1 of 4
CVE-2026-38835P2CRITICALCVSS 9.8v16.01.0.212026-04-21
CVE-2026-38835 [CRITICAL] CWE-77 CVE-2026-38835: Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the formSetUSB Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the formSetUSBPartitionUmount function via the usbPartitionName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
nvd
CVE-2026-24429P2CRITICALCVSS 9.8≤ 16.01.0.19\(5037\)2026-01-26
CVE-2026-24429 [CRITICAL] CWE-1393 CVE-2026-24429: Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) ship with a predefine Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) ship with a predefined default password for a built-in authentication account that is not required to be changed during initial configuration. An attacker can leverage these default credentials to gain authenticated access to the management interface.
nvd
CVE-2024-3880P2HIGHCVSS 8.8v1.0.1.25\(633\)2024-04-16
CVE-2024-3880 [HIGH] CWE-78 CVE-2024-3880: A vulnerability has been found in Tenda W30E 1.0.1.25(633) and classified as critical. This vulnerab A vulnerability has been found in Tenda W30E 1.0.1.25(633) and classified as critical. This vulnerability affects the function formWriteFacMac of the file /goform/WriteFacMac. The manipulation of the argument mac leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-260914 i
nvd
CVE-2024-3881P2HIGHCVSS 8.8v1.0.1.25\(633\)2024-04-16
CVE-2024-3881 [HIGH] CWE-121 CVE-2024-3881: A vulnerability was found in Tenda W30E 1.0.1.25(633) and classified as critical. This issue affects A vulnerability was found in Tenda W30E 1.0.1.25(633) and classified as critical. This issue affects the function frmL7PlotForm of the file /goform/frmL7ProtForm. The manipulation of the argument page leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated i
nvd
CVE-2024-4171P2HIGHCVSS 8.8v1.0.1.252024-04-25
CVE-2024-4171 [HIGH] CWE-121 CVE-2024-4171: A vulnerability classified as critical has been found in Tenda W30E 1.0/1.0.1.25. Affected is the fu A vulnerability classified as critical has been found in Tenda W30E 1.0/1.0.1.25. Affected is the function fromWizardHandle of the file /goform/WizardHandle. The manipulation of the argument PPW leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-261990 is
nvd
CVE-2024-3879P2HIGHCVSS 8.8v1.0.1.25\(633\)2024-04-16
CVE-2024-3879 [HIGH] CWE-121 CVE-2024-3879: A vulnerability, which was classified as critical, was found in Tenda W30E 1.0.1.25(633). This affec A vulnerability, which was classified as critical, was found in Tenda W30E 1.0.1.25(633). This affects the function formSetCfm of the file /goform/setcfm. The manipulation of the argument funcpara1 leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The ident
nvd
CVE-2024-3882P2HIGHCVSS 8.8v1.0.1.25\(633\)2024-04-16
CVE-2024-3882 [HIGH] CWE-121 CVE-2024-3882: A vulnerability was found in Tenda W30E 1.0.1.25(633). It has been classified as critical. Affected A vulnerability was found in Tenda W30E 1.0.1.25(633). It has been classified as critical. Affected is the function fromRouteStatic of the file /goform/fromRouteStatic. The manipulation of the argument page leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The
nvd
CVE-2023-49999P2CRITICALCVSS 9.8v16.01.0.12\(4843\)2023-12-07
CVE-2023-49999 [CRITICAL] CWE-787 CVE-2023-49999: Tenda W30E V16.01.0.12(4843) was discovered to contain a command injection vulnerability via the fun Tenda W30E V16.01.0.12(4843) was discovered to contain a command injection vulnerability via the function setUmountUSBPartition.
nvd
CVE-2023-49403P2CRITICALCVSS 9.8v16.01.0.12\(4843\)2023-12-07
CVE-2023-49403 [CRITICAL] CWE-787 CVE-2023-49403: Tenda W30E V16.01.0.12(4843) was discovered to contain a command injection vulnerability via the fun Tenda W30E V16.01.0.12(4843) was discovered to contain a command injection vulnerability via the function setFixTools.
nvd
CVE-2022-45506P2CRITICALCVSS 9.8v1.0.1.25\(633\)2022-12-08
CVE-2022-45506 [CRITICAL] CWE-78 CVE-2022-45506: Tenda W30E v1.0.1.25(633) was discovered to contain a command injection vulnerability via the fileNa Tenda W30E v1.0.1.25(633) was discovered to contain a command injection vulnerability via the fileNameMit parameter at /goform/delFileName.
nvd
CVE-2026-24428P2HIGHCVSS 8.8≤ 16.01.0.19\(5037\)2026-01-26
CVE-2026-24428 [HIGH] CWE-863 CVE-2026-24428: Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) contain an authorizat Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) contain an authorization flaw in the user management API that allows a low-privileged authenticated user to change the administrator account password. By sending a crafted request directly to the backend endpoint, an attacker can bypass role-based restrictions enforced by t
nvd
CVE-2026-24440P2HIGHCVSS 8.8≤ 16.01.0.19\(5037\)2026-01-26
CVE-2026-24440 [HIGH] CWE-620 CVE-2026-24440: Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) allow account passwor Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) allow account passwords to be changed through the maintenance interface without requiring verification of the existing password. This enables unauthorized password changes when access to the affected endpoint is obtained.
nvd
CVE-2023-49405P3CRITICALCVSS 9.8v16.01.0.12\(4843\)2023-12-07
CVE-2023-49405 [CRITICAL] CWE-787 CVE-2023-49405: Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function UploadCfg. Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function UploadCfg.
nvd
CVE-2023-49404P3CRITICALCVSS 9.8v16.01.0.12\(4843\)2023-12-07
CVE-2023-49404 [CRITICAL] CWE-787 CVE-2023-49404: Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formAdvance Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formAdvancedSetListSet.
nvd
CVE-2023-50001P3CRITICALCVSS 9.8v16.01.0.12\(4843\)2023-12-07
CVE-2023-50001 [CRITICAL] CWE-787 CVE-2023-50001: Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formUpgrade Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formUpgradeMeshOnline.
nvd
CVE-2023-50000P3CRITICALCVSS 9.8v16.01.0.12\(4843\)2023-12-07
CVE-2023-50000 [CRITICAL] CWE-787 CVE-2023-50000: Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formResetMe Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formResetMeshNode.
nvd
CVE-2023-49410P3CRITICALCVSS 9.8v16.01.0.12\(4843\)2023-12-07
CVE-2023-49410 [CRITICAL] CWE-787 CVE-2023-49410: Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function via the fun Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function via the function set_wan_status.
nvd
CVE-2023-49402P3CRITICALCVSS 9.8v16.01.0.12\(4843\)2023-12-07
CVE-2023-49402 [CRITICAL] CWE-787 CVE-2023-49402: Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function localMsg. Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function localMsg.
nvd
CVE-2023-50002P3CRITICALCVSS 9.8v16.01.0.12\(4843\)2023-12-07
CVE-2023-50002 [CRITICAL] CWE-787 CVE-2023-50002: Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formRebootM Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formRebootMeshNode.
nvd
CVE-2024-32286P3CRITICALCVSS 9.8v1.0.1.25\(633\)2024-04-17
CVE-2024-32286 [CRITICAL] CWE-125 CVE-2024-32286: Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability located via the page para Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability located via the page parameter in the fromVirtualSer function.
nvd