Tenda
Tenda W30e Firmware: vulnerabilidades y CVE
Tenda W30e Firmware tiene 63 vulnerabilidades publicadas, 13 de ellas en los últimos 12 meses. 18 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE63
Últimos 12 meses13
Críticas18
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-38835 | Crítica (9.8) | 2.6% | — | 21 abr 2026 | Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the formSetUSBPartitionUmount function via the usbPartitionName parameter. This vulnerability allows attackers to execute arbitrary… |
| CVE-2026-38834 | Alta (7.3) | 1.6% | — | 21 abr 2026 | Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the do_ping_action function via the hostName parameter. This vulnerability allows attackers to execute arbitrary commands via a… |
| CVE-2026-24440 | Alta (8.7) | 0.31% | — | 26 ene 2026 | Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) allow account passwords to be changed through the maintenance interface without requiring verification of the existing password. This… |
| CVE-2026-24439 | Baja (2.1) | 0.20% | — | 26 ene 2026 | Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) fail to include the X-Content-Type-Options: nosniff response header on web management interfaces. As a result, browsers that perform MIME… |
| CVE-2026-24437 | Media (4.8) | 0.17% | — | 26 ene 2026 | Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) serve sensitive administrative content without appropriate cache-control directives. As a result, browsers may store credential-bearing… |
| CVE-2026-24436 | Crítica (9.2) | 0.47% | — | 26 ene 2026 | Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) do not enforce rate limiting or account lockout mechanisms on authentication endpoints. This allows attackers to perform unrestricted… |
| CVE-2026-24435 | Alta (7.1) | 0.24% | — | 26 ene 2026 | Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) implement an insecure Cross-Origin Resource Sharing (CORS) policy on authenticated administrative endpoints. The device sets… |
| CVE-2026-24433 | Media (5.1) | 0.21% | — | 26 ene 2026 | Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) contain a stored cross-site scripting vulnerability in the user creation functionality. Insufficient input validation allows… |
| CVE-2026-24432 | Media (5.1) | 0.13% | — | 26 ene 2026 | Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) lack cross-site request forgery (CSRF) protections on administrative endpoints, including those used to change administrator account… |
| CVE-2026-24431 | Alta (7.1) | 0.21% | — | 26 ene 2026 | Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) display stored user account passwords in plaintext within the administrative web interface. Any user with access to the affected management… |
| CVE-2026-24430 | Alta (8.2) | 0.27% | — | 26 ene 2026 | Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) disclose sensitive account credentials in cleartext within HTTP responses generated by the maintenance interface. Because the management… |
| CVE-2026-24429 | Crítica (9.3) | 0.43% | — | 26 ene 2026 | Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) ship with a predefined default password for a built-in authentication account that is not required to be changed during initial… |
| CVE-2026-24428 | Alta (8.7) | 0.33% | — | 26 ene 2026 | Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) contain an authorization flaw in the user management API that allows a low-privileged authenticated user to change the administrator account… |
| CVE-2025-57086 | Alta (7.5) | 0.40% | — | 9 sept 2025 | Tenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the String parameter in the formDeleteMeshNode function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted… |
| CVE-2025-57085 | Crítica (9.8) | 0.47% | — | 9 sept 2025 | Tenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the v17 parameter in the UploadCfg function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. |
| CVE-2025-57087 | Alta (7.5) | 0.49% | — | 9 sept 2025 | Tenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the countryCode parameter in the werlessAdvancedSet function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a… |
| CVE-2024-52789 | Alta (8) | 0.41% | — | 19 nov 2024 | Tenda W30E v2.0 V16.01.0.8 was discovered to contain a hardcoded password vulnerability in /etc_ro/shadow, which allows attackers to log in as root. |
| CVE-2024-4171 | Alta (8.8) | 1.4% | — | 25 abr 2024 | A vulnerability classified as critical has been found in Tenda W30E 1.0/1.0.1.25. Affected is the function fromWizardHandle of the file /goform/WizardHandle. The manipulation of the argument PPW leads to stack-based… |
| CVE-2024-32293 | Alta (8) | 5.6% | — | 17 abr 2024 | Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability via the page parameter in the fromDhcpListClient function. |
| CVE-2024-32292 | Alta (8.8) | 1.7% | — | 17 abr 2024 | Tenda W30E v1.0 V1.0.1.25(633) firmware contains a command injection vulnerablility in the formexeCommand function via the cmdinput parameter. |
| CVE-2024-32291 | Alta (7.5) | 0.67% | — | 17 abr 2024 | Tenda W30E v1.0 firmware v1.0.1.25(633) has a stack overflow vulnerability via the page parameter in the fromNatlimit function. |
| CVE-2024-32290 | Media (6.7) | 0.66% | — | 17 abr 2024 | Tenda W30E v1.0 v1.0.1.25(633) firmware has a stack overflow vulnerability via the page parameter in the fromAddressNat function. |
| CVE-2024-32288 | Media (6.3) | 0.47% | — | 17 abr 2024 | Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability located via the page parameter in the fromwebExcptypemanFilter function. |
| CVE-2024-32287 | Media (6.5) | 0.51% | — | 17 abr 2024 | Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability via the qos parameter in the fromqossetting function. |
| CVE-2024-32286 | Crítica (9.8) | 0.78% | — | 17 abr 2024 | Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability located via the page parameter in the fromVirtualSer function. |
| CVE-2024-32285 | Alta (8) | 0.66% | — | 17 abr 2024 | Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability via the password parameter in the formaddUserName function. |
| CVE-2024-3882 | Alta (8.8) | 1.4% | — | 16 abr 2024 | A vulnerability was found in Tenda W30E 1.0.1.25(633). It has been classified as critical. Affected is the function fromRouteStatic of the file /goform/fromRouteStatic. The manipulation of the argument page leads to… |
| CVE-2024-3881 | Alta (8.8) | 1.5% | — | 16 abr 2024 | A vulnerability was found in Tenda W30E 1.0.1.25(633) and classified as critical. This issue affects the function frmL7PlotForm of the file /goform/frmL7ProtForm. The manipulation of the argument page leads to… |
| CVE-2024-3880 | Alta (8.8) | 4.4% | — | 16 abr 2024 | A vulnerability has been found in Tenda W30E 1.0.1.25(633) and classified as critical. This vulnerability affects the function formWriteFacMac of the file /goform/WriteFacMac. The manipulation of the argument mac leads… |
| CVE-2024-3879 | Alta (8.8) | 1.5% | — | 16 abr 2024 | A vulnerability, which was classified as critical, was found in Tenda W30E 1.0.1.25(633). This affects the function formSetCfm of the file /goform/setcfm. The manipulation of the argument funcpara1 leads to stack-based… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.