CVE-2024-46430

MEDIUM

Tenda W18E V16.01.0.8(1625) - Unauthenticated Password Change via setLoginPassword Function

Title source: llm
STIX 2.1

Description

Tenda W18E V16.01.0.8(1625) is vulnerable to Incorrect Access Control. Unauthorized password change via the web management portal allows an unauthenticated remote attacker to change the administrator password by sending a specially crafted HTTP POST request to the setLoginPassword function, bypassing the authentication mechanism.

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0005
EPSS Percentile 15.7%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-284
Status published
Products (1)
tenda/w18e_firmware 16.01.0.8\(1625\)
Published Feb 10, 2025
Tracked Since Feb 18, 2026