VYPR
Unrated severityNVD Advisory· Published Feb 10, 2025· Updated Feb 10, 2025

CVE-2024-46437

CVE-2024-46437

Description

A sensitive information disclosure vulnerability in the Tenda W18E V16.01.0.8(1625) web management portal allows an unauthenticated remote attacker to retrieve sensitive configuration information, including WiFi SSID, WiFi password, and base64-encoded administrator credentials, by sending a specially crafted HTTP POST request to the getQuickCfgWifiAndLogin function, bypassing authentication checks.

Affected products

2
  • Tenda/W18Edescription
  • Tenda/W18Ellm-fuzzy
    Range: = V16.01.0.8(1625)

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.