CVE-2026-24431

MEDIUM

Shenzhen Tenda W30E V2 - Info Disclosure

Title source: llm
STIX 2.1

Description

Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) display stored user account passwords in plaintext within the administrative web interface. Any user with access to the affected management pages can directly view credentials.

References (2)

Core 2

Scores

CVSS v3 6.5
EPSS 0.0001
EPSS Percentile 1.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-317
Status published
Products (2)
Shenzhen Tenda Technology Co., Ltd./W30E V2 < 16.01.0.19(5037)
tenda/w30e_firmware < 16.01.0.19\(5037\)
Published Jan 26, 2026
Tracked Since Feb 18, 2026