VYPR

W30e Firmware

by Tenda

CVEs (63)

  • CVE-2026-24437MedJan 26, 2026
    risk 0.36cvss 5.5epss 0.00

    Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) serve sensitive administrative content without appropriate cache-control directives. As a result, browsers may store credential-bearing responses locally, exposing them to subsequent unauthorized…

  • CVE-2026-24433MedJan 26, 2026
    risk 0.35cvss 5.4epss 0.00

    Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) contain a stored cross-site scripting vulnerability in the user creation functionality. Insufficient input validation allows attacker-controlled script content to be stored and later executed when…

  • CVE-2026-24432MedJan 26, 2026
    risk 0.28cvss 4.3epss 0.00

    Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) lack cross-site request forgery (CSRF) protections on administrative endpoints, including those used to change administrator account credentials. As a result, an attacker can craft malicious requests…

Page 4 of 4