cbcvebase.

Tenda W30E Firmware vulnerabilities

63 known vulnerabilities affecting tenda/w30e_firmware.

Total CVEs
63
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL18HIGH36MEDIUM9

Vulnerabilities

Page 2 of 4
CVE-2026-24436P3CRITICALCVSS 9.8≤ 16.01.0.19\(5037\)2026-01-26
CVE-2026-24436 [CRITICAL] CWE-307 CVE-2026-24436: Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) do not enforce rate l Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) do not enforce rate limiting or account lockout mechanisms on authentication endpoints. This allows attackers to perform unrestricted brute-force attempts against administrative credentials.
nvd
CVE-2023-49406P3CRITICALCVSS 9.8v16.01.0.12\(4843\)2023-12-07
CVE-2023-49406 [CRITICAL] CVE-2023-49406: Tenda W30E V16.01.0.12(4843) was discovered to contain a Command Execution vulnerability via the fun Tenda W30E V16.01.0.12(4843) was discovered to contain a Command Execution vulnerability via the function /goform/telnet.
nvd
CVE-2023-49411P3CRITICALCVSS 9.8v16.01.0.12\(4843\)2023-12-07
CVE-2023-49411 [CRITICAL] CWE-787 CVE-2023-49411: Tenda W30E V16.01.0.12(4843) contains a stack overflow vulnerability via the function formDeleteMesh Tenda W30E V16.01.0.12(4843) contains a stack overflow vulnerability via the function formDeleteMeshNode.
nvd
CVE-2026-38834P3HIGHCVSS 7.3v16.01.0.212026-04-21
CVE-2026-38834 [HIGH] CWE-77 CVE-2026-38834: Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the do_ping_ac Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the do_ping_action function via the hostName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
nvd
CVE-2024-32292P3HIGHCVSS 8.8v1.0.1.25\(633\)2024-04-17
CVE-2024-32292 [HIGH] CWE-77 CVE-2024-32292: Tenda W30E v1.0 V1.0.1.25(633) firmware contains a command injection vulnerablility in the formexeCo Tenda W30E v1.0 V1.0.1.25(633) firmware contains a command injection vulnerablility in the formexeCommand function via the cmdinput parameter.
nvd
CVE-2025-57085P3CRITICALCVSS 9.8≤ 16.01.0.19\(5037\)2025-09-09
CVE-2025-57085 [CRITICAL] CWE-121 CVE-2025-57085: Tenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the v17 parameter in the Tenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the v17 parameter in the UploadCfg function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
nvd
CVE-2024-32293P3HIGHCVSS 8.0v1.0.1.25\(633\)2024-04-17
CVE-2024-32293 [HIGH] CWE-121 CVE-2024-32293: Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability via the page parameter in Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability via the page parameter in the fromDhcpListClient function.
nvd
CVE-2023-25231P3CRITICALCVSS 9.8vv1.0.1.25\(633\)2023-02-27
CVE-2023-25231 [CRITICAL] CWE-787 CVE-2023-25231: Tenda Router W30E V1.0.1.25(633) is vulnerable to Buffer Overflow in function fromRouteStatic via pa Tenda Router W30E V1.0.1.25(633) is vulnerable to Buffer Overflow in function fromRouteStatic via parameters entrys and mitInterface.
nvd
CVE-2024-32285P3HIGHCVSS 8.0v1.0.1.25\(633\)2024-04-17
CVE-2024-32285 [HIGH] CWE-121 CVE-2024-32285: Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability via the password paramete Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability via the password parameter in the formaddUserName function.
nvd
CVE-2026-24430P3HIGHCVSS 7.5≤ 16.01.0.19\(5037\)2026-01-26
CVE-2026-24430 [HIGH] CWE-201 CVE-2026-24430: Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) disclose sensitive ac Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) disclose sensitive account credentials in cleartext within HTTP responses generated by the maintenance interface. Because the management interface is accessible over unencrypted HTTP by default, credentials may be exposed to network-based interception.
nvd
CVE-2022-45511P3HIGHCVSS 7.5v1.0.1.25\(633\)2022-12-08
CVE-2022-45511 [HIGH] CWE-787 CVE-2022-45511: Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the PPPOEPassword parameter Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the PPPOEPassword parameter at /goform/QuickIndex.
nvd
CVE-2022-45524P3HIGHCVSS 7.5v1.0.1.25\(633\)2022-12-08
CVE-2022-45524 [HIGH] CWE-787 CVE-2022-45524: Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the opttype parameter at /g Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the opttype parameter at /goform/IPSECsave.
nvd
CVE-2022-45519P3HIGHCVSS 7.5v1.0.1.25\(633\)2022-12-08
CVE-2022-45519 [HIGH] CWE-787 CVE-2022-45519: Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the Go parameter at /goform Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the Go parameter at /goform/SafeMacFilter.
nvd
CVE-2022-45515P3HIGHCVSS 7.5v1.0.1.25\(633\)2022-12-08
CVE-2022-45515 [HIGH] CWE-787 CVE-2022-45515: Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the entries parameter at /g Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the entries parameter at /goform/addressNat.
nvd
CVE-2022-45509P3HIGHCVSS 7.5v1.0.1.25\(633\)2022-12-08
CVE-2022-45509 [HIGH] CWE-787 CVE-2022-45509: Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the account parameter at /g Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the account parameter at /goform/addUserName.
nvd
CVE-2022-45508P3HIGHCVSS 7.5v1.0.1.25\(633\)2022-12-08
CVE-2022-45508 [HIGH] CWE-787 CVE-2022-45508: Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the new_account parameter a Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the new_account parameter at /goform/editUserName.
nvd
CVE-2022-45525P3HIGHCVSS 7.5v1.0.1.25\(633\)2022-12-08
CVE-2022-45525 [HIGH] CWE-787 CVE-2022-45525: Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the downaction parameter at Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the downaction parameter at /goform/CertListInfo.
nvd
CVE-2022-45505P3HIGHCVSS 7.5v1.0.1.25\(633\)2022-12-08
CVE-2022-45505 [HIGH] CWE-787 CVE-2022-45505: Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the cmdinput parameter at / Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the cmdinput parameter at /goform/exeCommand.
nvd
CVE-2022-45510P3HIGHCVSS 7.5v1.0.1.25\(633\)2022-12-08
CVE-2022-45510 [HIGH] CWE-787 CVE-2022-45510: Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the mit_ssid_index paramete Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the mit_ssid_index parameter at /goform/AdvSetWrlsafeset.
nvd
CVE-2022-45507P3HIGHCVSS 7.5v1.0.1.25\(633\)2022-12-08
CVE-2022-45507 [HIGH] CWE-787 CVE-2022-45507: Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the editNameMit parameter a Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the editNameMit parameter at /goform/editFileName.
nvd
Tenda W30E Firmware vulnerabilities | cvebase