Tenda

W30e

9 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.02%
  • Veröffentlicht 26.01.2026 17:46:54
  • Zuletzt bearbeitet 28.01.2026 20:11:24

Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) lack cross-site request forgery (CSRF) protections on administrative endpoints, including those used to change administrator account credentials. As a result, an attacker ...

  • EPSS 0.01%
  • Veröffentlicht 26.01.2026 17:40:41
  • Zuletzt bearbeitet 28.01.2026 20:14:45

Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) display stored user account passwords in plaintext within the administrative web interface. Any user with access to the affected management pages can directly view credent...

  • EPSS 0.11%
  • Veröffentlicht 26.01.2026 17:39:02
  • Zuletzt bearbeitet 29.01.2026 13:01:22

Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) ship with a predefined default password for a built-in authentication account that is not required to be changed during initial configuration. An attacker can leverage the...

Exploit
  • EPSS 0.1%
  • Veröffentlicht 09.09.2025 00:00:00
  • Zuletzt bearbeitet 18.09.2025 18:42:39

Tenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the countryCode parameter in the werlessAdvancedSet function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

Exploit
  • EPSS 0.1%
  • Veröffentlicht 09.09.2025 00:00:00
  • Zuletzt bearbeitet 17.09.2025 19:49:56

Tenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the String parameter in the formDeleteMeshNode function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

Exploit
  • EPSS 0.1%
  • Veröffentlicht 09.09.2025 00:00:00
  • Zuletzt bearbeitet 17.09.2025 19:50:45

Tenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the v17 parameter in the UploadCfg function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

  • EPSS 0.5%
  • Veröffentlicht 25.04.2024 14:15:10
  • Zuletzt bearbeitet 15.07.2025 17:48:49

A vulnerability classified as critical has been found in Tenda W30E 1.0/1.0.1.25. Affected is the function fromWizardHandle of the file /goform/WizardHandle. The manipulation of the argument PPW leads to stack-based buffer overflow. It is possible to...

Exploit
  • EPSS 0.15%
  • Veröffentlicht 17.04.2024 14:15:09
  • Zuletzt bearbeitet 17.03.2025 16:00:18

Tenda W30E v1.0 firmware v1.0.1.25(633) has a stack overflow vulnerability via the page parameter in the fromNatlimit function.

Exploit
  • EPSS 0.15%
  • Veröffentlicht 17.04.2024 14:15:08
  • Zuletzt bearbeitet 17.03.2025 16:00:01

Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability located via the page parameter in the fromwebExcptypemanFilter function.