VendorsTendaw30e_firmwareany version
Vulnerabilities

Tenda w30e Firmware any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

14CVEs
CVE-2026-24436
Tenda W30E V2 Lacks Rate Limiting on Authentication
Published 2026-01-26 · Analyzed
9.8EPSS 0.005
CVE-2025-57085
Tenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the v17 parameter in the UploadCfg function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
Published 2025-09-09 · Analyzed
9.8EPSS 0.005
CVE-2026-24429
Tenda W30E V2 Hardcoded Default Password for Built-in Account
Published 2026-01-26 · Analyzed
9.8EPSS 0.004
CVE-2026-24428
Tenda W30E V2 Incorrect Authorization Allows Administrator Password Change
Published 2026-01-26 · Analyzed
8.8EPSS 0.003
CVE-2026-24440
Tenda W30E V2 Allows Password Changes Without Verifying Current Password
Published 2026-01-26 · Analyzed
8.8EPSS 0.003
CVE-2026-24430
Tenda W30E V2 HTTP Responses Expose Plaintext Credentials
Published 2026-01-26 · Analyzed
8.2EPSS 0.003
CVE-2025-57087
Tenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the countryCode parameter in the werlessAdvancedSet function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
Published 2025-09-09 · Analyzed
7.5EPSS 0.005
CVE-2025-57086
Tenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the String parameter in the formDeleteMeshNode function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
Published 2025-09-09 · Analyzed
7.5EPSS 0.004
CVE-2026-24435
Tenda W30E V2 Permissive CORS Allows Cross-origin Data Access
Published 2026-01-26 · Analyzed
7.1EPSS 0.002
CVE-2026-24431
Tenda W30E V2 Web UI Reveals Passwords in Cleartext
Published 2026-01-26 · Analyzed
7.1EPSS 0.002
CVE-2026-24439
Tenda W30E V2 Lacks X-Content-Type-Options Header
Published 2026-01-26 · Analyzed
6.5EPSS 0.002
CVE-2026-24437
Tenda W30E V2 Missing Cache Controls for Credential-bearing Pages
Published 2026-01-26 · Analyzed
5.5EPSS 0.002
CVE-2026-24433
Tenda W30E V2 Stored XSS via Username Field
Published 2026-01-26 · Analyzed
5.4EPSS 0.002
CVE-2026-24432
Tenda W30E V2 Missing CSRF Protections for Administrative Actions
Published 2026-01-26 · Analyzed
5.1EPSS 0.001