Tenda W30E Firmware vulnerabilities
63 known vulnerabilities affecting tenda/w30e_firmware.
Total CVEs
63
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL18HIGH36MEDIUM9
Vulnerabilities
Page 1 of 4
CVE-2026-38835P2CRITICALCVSS 9.8v16.01.0.212026-04-21
CVE-2026-38835 [CRITICAL] CWE-77 CVE-2026-38835: Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the formSetUSB
Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the formSetUSBPartitionUmount function via the usbPartitionName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
nvd
CVE-2026-24429P2CRITICALCVSS 9.8≤ 16.01.0.19\(5037\)2026-01-26
CVE-2026-24429 [CRITICAL] CWE-1393 CVE-2026-24429: Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) ship with a predefine
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) ship with a predefined default password for a built-in authentication account that is not required to be changed during initial configuration. An attacker can leverage these default credentials to gain authenticated access to the management interface.
nvd
CVE-2024-3880P2HIGHCVSS 8.8v1.0.1.25\(633\)2024-04-16
CVE-2024-3880 [HIGH] CWE-78 CVE-2024-3880: A vulnerability has been found in Tenda W30E 1.0.1.25(633) and classified as critical. This vulnerab
A vulnerability has been found in Tenda W30E 1.0.1.25(633) and classified as critical. This vulnerability affects the function formWriteFacMac of the file /goform/WriteFacMac. The manipulation of the argument mac leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-260914 i
nvd
CVE-2024-3881P2HIGHCVSS 8.8v1.0.1.25\(633\)2024-04-16
CVE-2024-3881 [HIGH] CWE-121 CVE-2024-3881: A vulnerability was found in Tenda W30E 1.0.1.25(633) and classified as critical. This issue affects
A vulnerability was found in Tenda W30E 1.0.1.25(633) and classified as critical. This issue affects the function frmL7PlotForm of the file /goform/frmL7ProtForm. The manipulation of the argument page leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated i
nvd
CVE-2024-4171P2HIGHCVSS 8.8v1.0.1.252024-04-25
CVE-2024-4171 [HIGH] CWE-121 CVE-2024-4171: A vulnerability classified as critical has been found in Tenda W30E 1.0/1.0.1.25. Affected is the fu
A vulnerability classified as critical has been found in Tenda W30E 1.0/1.0.1.25. Affected is the function fromWizardHandle of the file /goform/WizardHandle. The manipulation of the argument PPW leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-261990 is
nvd
CVE-2024-3879P2HIGHCVSS 8.8v1.0.1.25\(633\)2024-04-16
CVE-2024-3879 [HIGH] CWE-121 CVE-2024-3879: A vulnerability, which was classified as critical, was found in Tenda W30E 1.0.1.25(633). This affec
A vulnerability, which was classified as critical, was found in Tenda W30E 1.0.1.25(633). This affects the function formSetCfm of the file /goform/setcfm. The manipulation of the argument funcpara1 leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The ident
nvd
CVE-2024-3882P2HIGHCVSS 8.8v1.0.1.25\(633\)2024-04-16
CVE-2024-3882 [HIGH] CWE-121 CVE-2024-3882: A vulnerability was found in Tenda W30E 1.0.1.25(633). It has been classified as critical. Affected
A vulnerability was found in Tenda W30E 1.0.1.25(633). It has been classified as critical. Affected is the function fromRouteStatic of the file /goform/fromRouteStatic. The manipulation of the argument page leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The
nvd
CVE-2023-49999P2CRITICALCVSS 9.8v16.01.0.12\(4843\)2023-12-07
CVE-2023-49999 [CRITICAL] CWE-787 CVE-2023-49999: Tenda W30E V16.01.0.12(4843) was discovered to contain a command injection vulnerability via the fun
Tenda W30E V16.01.0.12(4843) was discovered to contain a command injection vulnerability via the function setUmountUSBPartition.
nvd
CVE-2023-49403P2CRITICALCVSS 9.8v16.01.0.12\(4843\)2023-12-07
CVE-2023-49403 [CRITICAL] CWE-787 CVE-2023-49403: Tenda W30E V16.01.0.12(4843) was discovered to contain a command injection vulnerability via the fun
Tenda W30E V16.01.0.12(4843) was discovered to contain a command injection vulnerability via the function setFixTools.
nvd
CVE-2022-45506P2CRITICALCVSS 9.8v1.0.1.25\(633\)2022-12-08
CVE-2022-45506 [CRITICAL] CWE-78 CVE-2022-45506: Tenda W30E v1.0.1.25(633) was discovered to contain a command injection vulnerability via the fileNa
Tenda W30E v1.0.1.25(633) was discovered to contain a command injection vulnerability via the fileNameMit parameter at /goform/delFileName.
nvd
CVE-2026-24428P2HIGHCVSS 8.8≤ 16.01.0.19\(5037\)2026-01-26
CVE-2026-24428 [HIGH] CWE-863 CVE-2026-24428: Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) contain an authorizat
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) contain an authorization flaw in the user management API that allows a low-privileged authenticated user to change the administrator account password. By sending a crafted request directly to the backend endpoint, an attacker can bypass role-based restrictions enforced by t
nvd
CVE-2026-24440P2HIGHCVSS 8.8≤ 16.01.0.19\(5037\)2026-01-26
CVE-2026-24440 [HIGH] CWE-620 CVE-2026-24440: Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) allow account passwor
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) allow account passwords to be changed through the maintenance interface without requiring verification of the existing password. This enables unauthorized password changes when access to the affected endpoint is obtained.
nvd
CVE-2023-49405P3CRITICALCVSS 9.8v16.01.0.12\(4843\)2023-12-07
CVE-2023-49405 [CRITICAL] CWE-787 CVE-2023-49405: Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function UploadCfg.
Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function UploadCfg.
nvd
CVE-2023-49404P3CRITICALCVSS 9.8v16.01.0.12\(4843\)2023-12-07
CVE-2023-49404 [CRITICAL] CWE-787 CVE-2023-49404: Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formAdvance
Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formAdvancedSetListSet.
nvd
CVE-2023-50001P3CRITICALCVSS 9.8v16.01.0.12\(4843\)2023-12-07
CVE-2023-50001 [CRITICAL] CWE-787 CVE-2023-50001: Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formUpgrade
Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formUpgradeMeshOnline.
nvd
CVE-2023-50000P3CRITICALCVSS 9.8v16.01.0.12\(4843\)2023-12-07
CVE-2023-50000 [CRITICAL] CWE-787 CVE-2023-50000: Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formResetMe
Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formResetMeshNode.
nvd
CVE-2023-49410P3CRITICALCVSS 9.8v16.01.0.12\(4843\)2023-12-07
CVE-2023-49410 [CRITICAL] CWE-787 CVE-2023-49410: Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function via the fun
Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function via the function set_wan_status.
nvd
CVE-2023-49402P3CRITICALCVSS 9.8v16.01.0.12\(4843\)2023-12-07
CVE-2023-49402 [CRITICAL] CWE-787 CVE-2023-49402: Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function localMsg.
Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function localMsg.
nvd
CVE-2023-50002P3CRITICALCVSS 9.8v16.01.0.12\(4843\)2023-12-07
CVE-2023-50002 [CRITICAL] CWE-787 CVE-2023-50002: Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formRebootM
Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formRebootMeshNode.
nvd
CVE-2024-32286P3CRITICALCVSS 9.8v1.0.1.25\(633\)2024-04-17
CVE-2024-32286 [CRITICAL] CWE-125 CVE-2024-32286: Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability located via the page para
Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability located via the page parameter in the fromVirtualSer function.
nvd
1 / 4Next →