PT-2025-6091 · Tenda · Tenda W18E

Matthew Evans

·

Published

2023-02-10

·

Updated

2025-02-14

·

CVE-2024-46433

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tenda W18E version V16.01.0.8(1625)
Description A default credentials vulnerability allows unauthenticated remote attackers to access the web management portal using the default rzadmin account with administrative privileges.
Recommendations For Tenda W18E version V16.01.0.8(1625), consider changing the default rzadmin account credentials to prevent unauthorized access. As a temporary workaround, restrict access to the web management portal until a patch is available.

Exploit

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

BDU:2025-02062
CVE-2024-46433

Affected Products

Tenda W18E