VYPR

W30e Firmware

by Tenda

CVEs (63)

  • CVE-2024-4171HigApr 25, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability classified as critical has been found in Tenda W30E 1.0/1.0.1.25. Affected is the function fromWizardHandle of the file /goform/WizardHandle. The manipulation of the argument PPW leads to stack-based buffer overflow. It is possible to launch the attack remotely.…

  • CVE-2024-32292HigApr 17, 2024
    risk 0.57cvss 8.8epss 0.02

    Tenda W30E v1.0 V1.0.1.25(633) firmware contains a command injection vulnerablility in the formexeCommand function via the cmdinput parameter.

  • CVE-2024-3882HigApr 16, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in Tenda W30E 1.0.1.25(633). It has been classified as critical. Affected is the function fromRouteStatic of the file /goform/fromRouteStatic. The manipulation of the argument page leads to stack-based buffer overflow. It is possible to launch the…

  • CVE-2024-3881HigApr 16, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in Tenda W30E 1.0.1.25(633) and classified as critical. This issue affects the function frmL7PlotForm of the file /goform/frmL7ProtForm. The manipulation of the argument page leads to stack-based buffer overflow. The attack may be initiated remotely.…

  • CVE-2024-3879HigApr 16, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability, which was classified as critical, was found in Tenda W30E 1.0.1.25(633). This affects the function formSetCfm of the file /goform/setcfm. The manipulation of the argument funcpara1 leads to stack-based buffer overflow. It is possible to initiate the attack…

  • CVE-2024-52789HigNov 19, 2024
    risk 0.52cvss 8.0epss 0.00

    Tenda W30E v2.0 V16.01.0.8 was discovered to contain a hardcoded password vulnerability in /etc_ro/shadow, which allows attackers to log in as root.

  • CVE-2024-32293HigApr 17, 2024
    risk 0.52cvss 8.0epss 0.06

    Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability via the page parameter in the fromDhcpListClient function.

  • CVE-2024-32285HigApr 17, 2024
    risk 0.52cvss 8.0epss 0.01

    Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability via the password parameter in the formaddUserName function.

  • CVE-2026-24430HigJan 26, 2026
    risk 0.49cvss 7.5epss 0.00

    Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) disclose sensitive account credentials in cleartext within HTTP responses generated by the maintenance interface. Because the management interface is accessible over unencrypted HTTP by default,…

  • CVE-2025-57086HigSep 9, 2025
    risk 0.49cvss 7.5epss 0.00

    Tenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the String parameter in the formDeleteMeshNode function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

  • CVE-2025-57087HigSep 9, 2025
    risk 0.49cvss 7.5epss 0.00

    Tenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the countryCode parameter in the werlessAdvancedSet function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

  • CVE-2024-32291HigApr 17, 2024
    risk 0.49cvss 7.5epss 0.01

    Tenda W30E v1.0 firmware v1.0.1.25(633) has a stack overflow vulnerability via the page parameter in the fromNatlimit function.

  • CVE-2022-45525HigDec 8, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the downaction parameter at /goform/CertListInfo.

  • CVE-2022-45524HigDec 8, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the opttype parameter at /goform/IPSECsave.

  • CVE-2022-45523HigDec 8, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/L7Im.

  • CVE-2022-45522HigDec 8, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/SafeClientFilter.

  • CVE-2022-45521HigDec 8, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/SafeUrlFilter.

  • CVE-2022-45520HigDec 8, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/qossetting.

  • CVE-2022-45519HigDec 8, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the Go parameter at /goform/SafeMacFilter.

  • CVE-2022-45518HigDec 8, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/SetIpBind.