CVE-2026-24440

HIGH

Shenzhen Tenda W30E V2 - Info Disclosure

Title source: llm
STIX 2.1

Description

Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) allow account passwords to be changed through the maintenance interface without requiring verification of the existing password. This enables unauthorized password changes when access to the affected endpoint is obtained.

Scores

CVSS v3 8.8
EPSS 0.0006
EPSS Percentile 18.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-620
Status published
Products (1)
tenda/w30e_firmware < 16.01.0.19\(5037\)
Published Jan 26, 2026
Tracked Since Feb 18, 2026