VendorsTendaw30e2.0
Vulnerabilities

Tenda W30E 2.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

13CVEs
CVE-2026-38835
Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the formSetUSBPartitionUmount function via the usbPartitionName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Published 2026-04-21 · Analyzed
9.8EPSS 0.026
CVE-2026-24436
Tenda W30E V2 Lacks Rate Limiting on Authentication
Published 2026-01-26 · Analyzed
9.8EPSS 0.005
CVE-2026-24428
Tenda W30E V2 Incorrect Authorization Allows Administrator Password Change
Published 2026-01-26 · Analyzed
8.8EPSS 0.003
CVE-2026-24440
Tenda W30E V2 Allows Password Changes Without Verifying Current Password
Published 2026-01-26 · Analyzed
8.8EPSS 0.003
CVE-2026-24430
Tenda W30E V2 HTTP Responses Expose Plaintext Credentials
Published 2026-01-26 · Analyzed
8.2EPSS 0.003
CVE-2024-52789
Tenda W30E v2.0 V16.01.0.8 was discovered to contain a hardcoded password vulnerability in /etc_ro/shadow, which allows attackers to log in as root.
Published 2024-11-19 · Analyzed
8.0EPSS 0.004
CVE-2025-57087
Tenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the countryCode parameter in the werlessAdvancedSet function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
Published 2025-09-09 · Analyzed
7.5EPSS 0.005
CVE-2026-38834
Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the do_ping_action function via the hostName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Published 2026-04-21 · Analyzed
7.3EPSS 0.016
CVE-2026-24435
Tenda W30E V2 Permissive CORS Allows Cross-origin Data Access
Published 2026-01-26 · Analyzed
7.1EPSS 0.002
CVE-2026-24431
Tenda W30E V2 Web UI Reveals Passwords in Cleartext
Published 2026-01-26 · Analyzed
7.1EPSS 0.002
CVE-2026-24439
Tenda W30E V2 Lacks X-Content-Type-Options Header
Published 2026-01-26 · Analyzed
6.5EPSS 0.002
CVE-2026-24437
Tenda W30E V2 Missing Cache Controls for Credential-bearing Pages
Published 2026-01-26 · Analyzed
5.5EPSS 0.002
CVE-2026-24433
Tenda W30E V2 Stored XSS via Username Field
Published 2026-01-26 · Analyzed
5.4EPSS 0.002