VYPR

W30E

by Tenda

Source repositories

CVEs (53)

  • CVE-2022-45512HigDec 8, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/SafeEmailFilter.

  • CVE-2022-45511HigDec 8, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the PPPOEPassword parameter at /goform/QuickIndex.

  • CVE-2022-45510HigDec 8, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the mit_ssid_index parameter at /goform/AdvSetWrlsafeset.

  • CVE-2022-45509HigDec 8, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the account parameter at /goform/addUserName.

  • CVE-2022-45508HigDec 8, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the new_account parameter at /goform/editUserName.

  • CVE-2022-45507HigDec 8, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the editNameMit parameter at /goform/editFileName.

  • CVE-2022-45505HigDec 8, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the cmdinput parameter at /goform/exeCommand.

  • CVE-2026-38834HigApr 21, 2026
    risk 0.48cvss 7.3epss 0.01

    Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the do_ping_action function via the hostName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

  • CVE-2024-32290MedApr 17, 2024
    risk 0.44cvss 6.7epss 0.01

    Tenda W30E v1.0 v1.0.1.25(633) firmware has a stack overflow vulnerability via the page parameter in the fromAddressNat function.

  • CVE-2026-24435MedJan 26, 2026
    risk 0.42cvss 6.5epss 0.00

    Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) implement an insecure Cross-Origin Resource Sharing (CORS) policy on authenticated administrative endpoints. The device sets Access-Control-Allow-Origin: * in combination with…

  • CVE-2024-32287MedApr 17, 2024
    risk 0.42cvss 6.5epss 0.01

    Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability via the qos parameter in the fromqossetting function.

  • CVE-2024-32288MedApr 17, 2024
    risk 0.41cvss 6.3epss 0.00

    Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability located via the page parameter in the fromwebExcptypemanFilter function.

  • CVE-2024-3880MedApr 16, 2024
    risk 0.41cvss 6.3epss 0.04

    A vulnerability has been found in Tenda W30E 1.0.1.25(633) and classified as critical. This vulnerability affects the function formWriteFacMac of the file /goform/WriteFacMac. The manipulation of the argument mac leads to os command injection. The attack can be initiated…

Page 3 of 3