VendorsTendaw30eall versions
Vulnerabilities

Tenda W30E

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

63CVEs
CVE-2026-38835
Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the formSetUSBPartitionUmount function via the usbPartitionName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Published 2026-04-21 · Analyzed
9.8EPSS 0.026
CVE-2022-45506
Tenda W30E v1.0.1.25(633) was discovered to contain a command injection vulnerability via the fileNameMit parameter at /goform/delFileName.
Published 2022-12-08 · Modified
9.8EPSS 0.025
CVE-2023-49403
Tenda W30E V16.01.0.12(4843) was discovered to contain a command injection vulnerability via the function setFixTools.
Published 2023-12-07 · Modified
9.8EPSS 0.022
CVE-2023-49999
Tenda W30E V16.01.0.12(4843) was discovered to contain a command injection vulnerability via the function setUmountUSBPartition.
Published 2023-12-07 · Modified
9.8EPSS 0.022
CVE-2023-49406
Tenda W30E V16.01.0.12(4843) was discovered to contain a Command Execution vulnerability via the function /goform/telnet.
Published 2023-12-07 · Modified
9.8EPSS 0.015
CVE-2023-25231
Tenda Router W30E V1.0.1.25(633) is vulnerable to Buffer Overflow in function fromRouteStatic via parameters entrys and mitInterface.
Published 2023-02-27 · Modified
9.8EPSS 0.010
CVE-2023-49411
Tenda W30E V16.01.0.12(4843) contains a stack overflow vulnerability via the function formDeleteMeshNode.
Published 2023-12-07 · Modified
9.8EPSS 0.009
CVE-2023-49404
Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formAdvancedSetListSet.
Published 2023-12-07 · Modified
9.8EPSS 0.009
CVE-2023-49405
Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function UploadCfg.
Published 2023-12-07 · Modified
9.8EPSS 0.009
CVE-2023-50002
Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formRebootMeshNode.
Published 2023-12-07 · Modified
9.8EPSS 0.009
CVE-2023-50000
Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formResetMeshNode.
Published 2023-12-07 · Modified
9.8EPSS 0.009
CVE-2023-50001
Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formUpgradeMeshOnline.
Published 2023-12-07 · Modified
9.8EPSS 0.009
CVE-2023-49402
Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function localMsg.
Published 2023-12-07 · Modified
9.8EPSS 0.009
CVE-2023-49410
Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function via the function set_wan_status.
Published 2023-12-07 · Modified
9.8EPSS 0.009
CVE-2024-32286
Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability located via the page parameter in the fromVirtualSer function.
Published 2024-04-17 · Analyzed
9.8EPSS 0.008
CVE-2026-24436
Tenda W30E V2 Lacks Rate Limiting on Authentication
Published 2026-01-26 · Analyzed
9.8EPSS 0.005
CVE-2025-57085
Tenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the v17 parameter in the UploadCfg function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
Published 2025-09-09 · Analyzed
9.8EPSS 0.005
CVE-2026-24429
Tenda W30E V2 Hardcoded Default Password for Built-in Account
Published 2026-01-26 · Analyzed
9.8EPSS 0.004
CVE-2024-3881
Tenda W30E frmL7ProtForm frmL7PlotForm stack-based overflow
Published 2024-04-16 · Analyzed
9.0EPSS 0.015
CVE-2024-3879
Tenda W30E setcfm formSetCfm stack-based overflow
Published 2024-04-16 · Analyzed
9.0EPSS 0.015
CVE-2024-3882
Tenda W30E fromRouteStatic stack-based overflow
Published 2024-04-16 · Analyzed
9.0EPSS 0.014
CVE-2024-4171
Tenda W30E WizardHandle fromWizardHandle stack-based overflow
Published 2024-04-25 · Analyzed
9.0EPSS 0.014
CVE-2024-3880
Tenda W30E WriteFacMac formWriteFacMac os command injection
Published 2024-04-16 · Analyzed
8.8EPSS 0.044
CVE-2024-32292
Tenda W30E v1.0 V1.0.1.25(633) firmware contains a command injection vulnerablility in the formexeCommand function via the cmdinput parameter.
Published 2024-04-17 · Analyzed
8.8EPSS 0.017
CVE-2026-24428
Tenda W30E V2 Incorrect Authorization Allows Administrator Password Change
Published 2026-01-26 · Analyzed
8.8EPSS 0.003
CVE-2026-24440
Tenda W30E V2 Allows Password Changes Without Verifying Current Password
Published 2026-01-26 · Analyzed
8.8EPSS 0.003
CVE-2026-24430
Tenda W30E V2 HTTP Responses Expose Plaintext Credentials
Published 2026-01-26 · Analyzed
8.2EPSS 0.003
CVE-2024-32293
Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability via the page parameter in the fromDhcpListClient function.
Published 2024-04-17 · Analyzed
8.0EPSS 0.056
CVE-2024-32285
Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability via the password parameter in the formaddUserName function.
Published 2024-04-17 · Analyzed
8.0EPSS 0.007
CVE-2024-52789
Tenda W30E v2.0 V16.01.0.8 was discovered to contain a hardcoded password vulnerability in /etc_ro/shadow, which allows attackers to log in as root.
Published 2024-11-19 · Analyzed
8.0EPSS 0.004
CVE-2022-45511
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the PPPOEPassword parameter at /goform/QuickIndex.
Published 2022-12-08 · Modified
7.5EPSS 0.010
CVE-2022-45520
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/qossetting.
Published 2022-12-08 · Modified
7.5EPSS 0.009
CVE-2022-45512
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/SafeEmailFilter.
Published 2022-12-08 · Modified
7.5EPSS 0.009
CVE-2022-45521
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/SafeUrlFilter.
Published 2022-12-08 · Modified
7.5EPSS 0.009
CVE-2022-45513
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/P2pListFilter.
Published 2022-12-08 · Modified
7.5EPSS 0.009
CVE-2022-45508
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the new_account parameter at /goform/editUserName.
Published 2022-12-08 · Modified
7.5EPSS 0.009
CVE-2022-45522
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/SafeClientFilter.
Published 2022-12-08 · Modified
7.5EPSS 0.009
CVE-2022-45505
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the cmdinput parameter at /goform/exeCommand.
Published 2022-12-08 · Modified
7.5EPSS 0.009
CVE-2022-45523
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/L7Im.
Published 2022-12-08 · Modified
7.5EPSS 0.009
CVE-2022-45524
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the opttype parameter at /goform/IPSECsave.
Published 2022-12-08 · Modified
7.5EPSS 0.009
1 / 2Next →