W30e Firmware
by Tenda
CVEs (63)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-45517 | Hig | 0.49 | 7.5 | 0.01 | Dec 8, 2022 | Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/VirtualSer. | ||
| CVE-2022-45516 | Hig | 0.49 | 7.5 | 0.01 | Dec 8, 2022 | Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/NatStaticSetting. | ||
| CVE-2022-45515 | Hig | 0.49 | 7.5 | 0.01 | Dec 8, 2022 | Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the entries parameter at /goform/addressNat. | ||
| CVE-2022-45514 | Hig | 0.49 | 7.5 | 0.01 | Dec 8, 2022 | Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/webExcptypemanFilter. | ||
| CVE-2022-45513 | Hig | 0.49 | 7.5 | 0.01 | Dec 8, 2022 | Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/P2pListFilter. | ||
| CVE-2022-45512 | Hig | 0.49 | 7.5 | 0.01 | Dec 8, 2022 | Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/SafeEmailFilter. | ||
| CVE-2022-45511 | Hig | 0.49 | 7.5 | 0.01 | Dec 8, 2022 | Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the PPPOEPassword parameter at /goform/QuickIndex. | ||
| CVE-2022-45510 | Hig | 0.49 | 7.5 | 0.01 | Dec 8, 2022 | Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the mit_ssid_index parameter at /goform/AdvSetWrlsafeset. | ||
| CVE-2022-45509 | Hig | 0.49 | 7.5 | 0.01 | Dec 8, 2022 | Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the account parameter at /goform/addUserName. | ||
| CVE-2022-45508 | Hig | 0.49 | 7.5 | 0.01 | Dec 8, 2022 | Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the new_account parameter at /goform/editUserName. | ||
| CVE-2022-45507 | Hig | 0.49 | 7.5 | 0.01 | Dec 8, 2022 | Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the editNameMit parameter at /goform/editFileName. | ||
| CVE-2022-45505 | Hig | 0.49 | 7.5 | 0.01 | Dec 8, 2022 | Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the cmdinput parameter at /goform/exeCommand. | ||
| CVE-2026-38834 | Hig | 0.48 | 7.3 | 0.01 | Apr 21, 2026 | Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the do_ping_action function via the hostName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request. | ||
| CVE-2024-32290 | Med | 0.44 | 6.7 | 0.01 | Apr 17, 2024 | Tenda W30E v1.0 v1.0.1.25(633) firmware has a stack overflow vulnerability via the page parameter in the fromAddressNat function. | ||
| CVE-2026-24439 | Med | 0.42 | 6.5 | 0.00 | Jan 26, 2026 | Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) fail to include the X-Content-Type-Options: nosniff response header on web management interfaces. As a result, browsers that perform MIME sniffing may incorrectly interpret attacker-influenced… | ||
| CVE-2026-24435 | Med | 0.42 | 6.5 | 0.00 | Jan 26, 2026 | Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) implement an insecure Cross-Origin Resource Sharing (CORS) policy on authenticated administrative endpoints. The device sets Access-Control-Allow-Origin: * in combination with… | ||
| CVE-2026-24431 | Med | 0.42 | 6.5 | 0.00 | Jan 26, 2026 | Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) display stored user account passwords in plaintext within the administrative web interface. Any user with access to the affected management pages can directly view credentials. | ||
| CVE-2024-32287 | Med | 0.42 | 6.5 | 0.01 | Apr 17, 2024 | Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability via the qos parameter in the fromqossetting function. | ||
| CVE-2024-32288 | Med | 0.41 | 6.3 | 0.00 | Apr 17, 2024 | Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability located via the page parameter in the fromwebExcptypemanFilter function. | ||
| CVE-2024-3880 | Med | 0.41 | 6.3 | 0.04 | Apr 16, 2024 | A vulnerability has been found in Tenda W30E 1.0.1.25(633) and classified as critical. This vulnerability affects the function formWriteFacMac of the file /goform/WriteFacMac. The manipulation of the argument mac leads to os command injection. The attack can be initiated… |
- risk 0.49cvss 7.5epss 0.01
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/VirtualSer.
- risk 0.49cvss 7.5epss 0.01
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/NatStaticSetting.
- risk 0.49cvss 7.5epss 0.01
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the entries parameter at /goform/addressNat.
- risk 0.49cvss 7.5epss 0.01
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/webExcptypemanFilter.
- risk 0.49cvss 7.5epss 0.01
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/P2pListFilter.
- risk 0.49cvss 7.5epss 0.01
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/SafeEmailFilter.
- risk 0.49cvss 7.5epss 0.01
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the PPPOEPassword parameter at /goform/QuickIndex.
- risk 0.49cvss 7.5epss 0.01
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the mit_ssid_index parameter at /goform/AdvSetWrlsafeset.
- risk 0.49cvss 7.5epss 0.01
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the account parameter at /goform/addUserName.
- risk 0.49cvss 7.5epss 0.01
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the new_account parameter at /goform/editUserName.
- risk 0.49cvss 7.5epss 0.01
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the editNameMit parameter at /goform/editFileName.
- risk 0.49cvss 7.5epss 0.01
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the cmdinput parameter at /goform/exeCommand.
- risk 0.48cvss 7.3epss 0.01
Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the do_ping_action function via the hostName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
- risk 0.44cvss 6.7epss 0.01
Tenda W30E v1.0 v1.0.1.25(633) firmware has a stack overflow vulnerability via the page parameter in the fromAddressNat function.
- risk 0.42cvss 6.5epss 0.00
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) fail to include the X-Content-Type-Options: nosniff response header on web management interfaces. As a result, browsers that perform MIME sniffing may incorrectly interpret attacker-influenced…
- risk 0.42cvss 6.5epss 0.00
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) implement an insecure Cross-Origin Resource Sharing (CORS) policy on authenticated administrative endpoints. The device sets Access-Control-Allow-Origin: * in combination with…
- risk 0.42cvss 6.5epss 0.00
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) display stored user account passwords in plaintext within the administrative web interface. Any user with access to the affected management pages can directly view credentials.
- risk 0.42cvss 6.5epss 0.01
Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability via the qos parameter in the fromqossetting function.
- risk 0.41cvss 6.3epss 0.00
Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability located via the page parameter in the fromwebExcptypemanFilter function.
- risk 0.41cvss 6.3epss 0.04
A vulnerability has been found in Tenda W30E 1.0.1.25(633) and classified as critical. This vulnerability affects the function formWriteFacMac of the file /goform/WriteFacMac. The manipulation of the argument mac leads to os command injection. The attack can be initiated…
Page 3 of 4