Tenda W30E Firmware vulnerabilities
63 known vulnerabilities affecting tenda/w30e_firmware.
Total CVEs
63
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL18HIGH36MEDIUM9
Vulnerabilities
Page 4 of 4
CVE-2026-24437P4MEDIUMCVSS 5.5≤ 16.01.0.19\(5037\)2026-01-26
CVE-2026-24437 [MEDIUM] CWE-525 CVE-2026-24437: Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) serve sensitive admin
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) serve sensitive administrative content without appropriate cache-control directives. As a result, browsers may store credential-bearing responses locally, exposing them to subsequent unauthorized access.
nvd
CVE-2026-24433P4MEDIUMCVSS 5.4≤ 16.01.0.19\(5037\)2026-01-26
CVE-2026-24433 [MEDIUM] CWE-79 CVE-2026-24433: Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) contain a stored cros
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) contain a stored cross-site scripting vulnerability in the user creation functionality. Insufficient input validation allows attacker-controlled script content to be stored and later executed when administrative users access the affected management pages.
nvd
CVE-2026-24432P4MEDIUMCVSS 4.3≤ 16.01.0.19\(5037\)2026-01-26
CVE-2026-24432 [MEDIUM] CWE-352 CVE-2026-24432: Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) lack cross-site reque
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) lack cross-site request forgery (CSRF) protections on administrative endpoints, including those used to change administrator account credentials. As a result, an attacker can craft malicious requests that, when triggered by an authenticated user’s browser, modify administ
nvd
← Previous4 / 4