CVE-2026-24436

CRITICAL

Shenzhen Tenda W30E V2 - Auth Bypass

Title source: llm
STIX 2.1

Description

Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) do not enforce rate limiting or account lockout mechanisms on authentication endpoints. This allows attackers to perform unrestricted brute-force attempts against administrative credentials.

Scores

CVSS v3 9.8
EPSS 0.0004
EPSS Percentile 12.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-307
Status published
Products (1)
tenda/w30e_firmware < 16.01.0.19\(5037\)
Published Jan 26, 2026
Tracked Since Feb 18, 2026