W30e Firmware
by Tenda
CVEs (63)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-38835 | Cri | 0.64 | 9.8 | 0.02 | Apr 21, 2026 | Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the formSetUSBPartitionUmount function via the usbPartitionName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request. | ||
| CVE-2026-24436 | Cri | 0.64 | 9.8 | 0.00 | Jan 26, 2026 | Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) do not enforce rate limiting or account lockout mechanisms on authentication endpoints. This allows attackers to perform unrestricted brute-force attempts against administrative credentials. | ||
| CVE-2026-24429 | Cri | 0.64 | 9.8 | 0.00 | Jan 26, 2026 | Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) ship with a predefined default password for a built-in authentication account that is not required to be changed during initial configuration. An attacker can leverage these default credentials to… | ||
| CVE-2025-57085 | Cri | 0.64 | 9.8 | 0.00 | Sep 9, 2025 | Tenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the v17 parameter in the UploadCfg function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | ||
| CVE-2024-32286 | Cri | 0.64 | 9.8 | 0.01 | Apr 17, 2024 | Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability located via the page parameter in the fromVirtualSer function. | ||
| CVE-2023-49411 | Cri | 0.64 | 9.8 | 0.01 | Dec 7, 2023 | Tenda W30E V16.01.0.12(4843) contains a stack overflow vulnerability via the function formDeleteMeshNode. | ||
| CVE-2023-49406 | Cri | 0.64 | 9.8 | 0.02 | Dec 7, 2023 | Tenda W30E V16.01.0.12(4843) was discovered to contain a Command Execution vulnerability via the function /goform/telnet. | ||
| CVE-2023-49405 | Cri | 0.64 | 9.8 | 0.01 | Dec 7, 2023 | Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function UploadCfg. | ||
| CVE-2023-49404 | Cri | 0.64 | 9.8 | 0.01 | Dec 7, 2023 | Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formAdvancedSetListSet. | ||
| CVE-2023-50002 | Cri | 0.64 | 9.8 | 0.01 | Dec 7, 2023 | Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formRebootMeshNode. | ||
| CVE-2023-50001 | Cri | 0.64 | 9.8 | 0.01 | Dec 7, 2023 | Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formUpgradeMeshOnline. | ||
| CVE-2023-50000 | Cri | 0.64 | 9.8 | 0.01 | Dec 7, 2023 | Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formResetMeshNode. | ||
| CVE-2023-49999 | Cri | 0.64 | 9.8 | 0.02 | Dec 7, 2023 | Tenda W30E V16.01.0.12(4843) was discovered to contain a command injection vulnerability via the function setUmountUSBPartition. | ||
| CVE-2023-49410 | Cri | 0.64 | 9.8 | 0.01 | Dec 7, 2023 | Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function via the function set_wan_status. | ||
| CVE-2023-49403 | Cri | 0.64 | 9.8 | 0.02 | Dec 7, 2023 | Tenda W30E V16.01.0.12(4843) was discovered to contain a command injection vulnerability via the function setFixTools. | ||
| CVE-2023-49402 | Cri | 0.64 | 9.8 | 0.01 | Dec 7, 2023 | Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function localMsg. | ||
| CVE-2023-25231 | Cri | 0.64 | 9.8 | 0.01 | Feb 27, 2023 | Tenda Router W30E V1.0.1.25(633) is vulnerable to Buffer Overflow in function fromRouteStatic via parameters entrys and mitInterface. | ||
| CVE-2022-45506 | Cri | 0.64 | 9.8 | 0.02 | Dec 8, 2022 | Tenda W30E v1.0.1.25(633) was discovered to contain a command injection vulnerability via the fileNameMit parameter at /goform/delFileName. | ||
| CVE-2026-24440 | Hig | 0.57 | 8.8 | 0.00 | Jan 26, 2026 | Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) allow account passwords to be changed through the maintenance interface without requiring verification of the existing password. This enables unauthorized password changes when access to the affected… | ||
| CVE-2026-24428 | Hig | 0.57 | 8.8 | 0.00 | Jan 26, 2026 | Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) contain an authorization flaw in the user management API that allows a low-privileged authenticated user to change the administrator account password. By sending a crafted request directly to the… |
- risk 0.64cvss 9.8epss 0.02
Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the formSetUSBPartitionUmount function via the usbPartitionName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
- risk 0.64cvss 9.8epss 0.00
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) do not enforce rate limiting or account lockout mechanisms on authentication endpoints. This allows attackers to perform unrestricted brute-force attempts against administrative credentials.
- risk 0.64cvss 9.8epss 0.00
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) ship with a predefined default password for a built-in authentication account that is not required to be changed during initial configuration. An attacker can leverage these default credentials to…
- risk 0.64cvss 9.8epss 0.00
Tenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the v17 parameter in the UploadCfg function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
- risk 0.64cvss 9.8epss 0.01
Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability located via the page parameter in the fromVirtualSer function.
- risk 0.64cvss 9.8epss 0.01
Tenda W30E V16.01.0.12(4843) contains a stack overflow vulnerability via the function formDeleteMeshNode.
- risk 0.64cvss 9.8epss 0.02
Tenda W30E V16.01.0.12(4843) was discovered to contain a Command Execution vulnerability via the function /goform/telnet.
- risk 0.64cvss 9.8epss 0.01
Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function UploadCfg.
- risk 0.64cvss 9.8epss 0.01
Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formAdvancedSetListSet.
- risk 0.64cvss 9.8epss 0.01
Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formRebootMeshNode.
- risk 0.64cvss 9.8epss 0.01
Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formUpgradeMeshOnline.
- risk 0.64cvss 9.8epss 0.01
Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formResetMeshNode.
- risk 0.64cvss 9.8epss 0.02
Tenda W30E V16.01.0.12(4843) was discovered to contain a command injection vulnerability via the function setUmountUSBPartition.
- risk 0.64cvss 9.8epss 0.01
Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function via the function set_wan_status.
- risk 0.64cvss 9.8epss 0.02
Tenda W30E V16.01.0.12(4843) was discovered to contain a command injection vulnerability via the function setFixTools.
- risk 0.64cvss 9.8epss 0.01
Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function localMsg.
- risk 0.64cvss 9.8epss 0.01
Tenda Router W30E V1.0.1.25(633) is vulnerable to Buffer Overflow in function fromRouteStatic via parameters entrys and mitInterface.
- risk 0.64cvss 9.8epss 0.02
Tenda W30E v1.0.1.25(633) was discovered to contain a command injection vulnerability via the fileNameMit parameter at /goform/delFileName.
- risk 0.57cvss 8.8epss 0.00
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) allow account passwords to be changed through the maintenance interface without requiring verification of the existing password. This enables unauthorized password changes when access to the affected…
- risk 0.57cvss 8.8epss 0.00
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) contain an authorization flaw in the user management API that allows a low-privileged authenticated user to change the administrator account password. By sending a crafted request directly to the…
Page 1 of 4