VendorsTendaw30eall versions
Vulnerabilities

Tenda W30E

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

63CVEs
CVE-2022-45516
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/NatStaticSetting.
Published 2022-12-08 · Modified
7.5EPSS 0.009
CVE-2022-45517
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/VirtualSer.
Published 2022-12-08 · Modified
7.5EPSS 0.009
CVE-2022-45518
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/SetIpBind.
Published 2022-12-08 · Modified
7.5EPSS 0.009
CVE-2022-45520
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/qossetting.
Published 2022-12-08 · Modified
7.5EPSS 0.009
CVE-2022-45521
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/SafeUrlFilter.
Published 2022-12-08 · Modified
7.5EPSS 0.009
CVE-2022-45519
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the Go parameter at /goform/SafeMacFilter.
Published 2022-12-08 · Modified
7.5EPSS 0.009
CVE-2022-45522
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/SafeClientFilter.
Published 2022-12-08 · Modified
7.5EPSS 0.009
CVE-2022-45525
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the downaction parameter at /goform/CertListInfo.
Published 2022-12-08 · Modified
7.5EPSS 0.009
CVE-2022-45523
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/L7Im.
Published 2022-12-08 · Modified
7.5EPSS 0.009
CVE-2022-45507
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the editNameMit parameter at /goform/editFileName.
Published 2022-12-08 · Modified
7.5EPSS 0.008
CVE-2024-32291
Tenda W30E v1.0 firmware v1.0.1.25(633) has a stack overflow vulnerability via the page parameter in the fromNatlimit function.
Published 2024-04-17 · Analyzed
7.5EPSS 0.007
CVE-2025-57087
Tenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the countryCode parameter in the werlessAdvancedSet function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
Published 2025-09-09 · Analyzed
7.5EPSS 0.005
CVE-2025-57086
Tenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the String parameter in the formDeleteMeshNode function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
Published 2025-09-09 · Analyzed
7.5EPSS 0.004
CVE-2026-38834
Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the do_ping_action function via the hostName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Published 2026-04-21 · Analyzed
7.3EPSS 0.016
CVE-2026-24435
Tenda W30E V2 Permissive CORS Allows Cross-origin Data Access
Published 2026-01-26 · Analyzed
7.1EPSS 0.002
CVE-2026-24431
Tenda W30E V2 Web UI Reveals Passwords in Cleartext
Published 2026-01-26 · Analyzed
7.1EPSS 0.002
CVE-2024-32290
Tenda W30E v1.0 v1.0.1.25(633) firmware has a stack overflow vulnerability via the page parameter in the fromAddressNat function.
Published 2024-04-17 · Analyzed
6.7EPSS 0.007
CVE-2024-32287
Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability via the qos parameter in the fromqossetting function.
Published 2024-04-17 · Analyzed
6.5EPSS 0.005
CVE-2026-24439
Tenda W30E V2 Lacks X-Content-Type-Options Header
Published 2026-01-26 · Analyzed
6.5EPSS 0.002
CVE-2024-32288
Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability located via the page parameter in the fromwebExcptypemanFilter function.
Published 2024-04-17 · Analyzed
6.3EPSS 0.005
CVE-2026-24437
Tenda W30E V2 Missing Cache Controls for Credential-bearing Pages
Published 2026-01-26 · Analyzed
5.5EPSS 0.002
CVE-2026-24433
Tenda W30E V2 Stored XSS via Username Field
Published 2026-01-26 · Analyzed
5.4EPSS 0.002
CVE-2026-24432
Tenda W30E V2 Missing CSRF Protections for Administrative Actions
Published 2026-01-26 · Analyzed
5.1EPSS 0.001
← Prev2 / 2