PT-2026-4788 · Tenda · Tenda W30E
Kazuma Matsumoto
·
Publicado
2026-01-26
·
Atualizado
2026-01-29
·
CVE-2026-24428
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037)
Description
The firmware contains an authorization flaw within the user management API. A low-privileged authenticated user can alter the administrator account password by submitting a specially crafted request to the backend endpoint. This bypasses role-based access controls enforced by the web interface, potentially granting an attacker full administrative privileges. The vulnerable API endpoint allows unauthorized modification of administrative credentials.
Recommendations
Update firmware to a version later than V16.01.0.19(5037).
Correção
Incorrect Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Tenda W30E