PT-2026-22594 · Tenda · Tenda W20E

Akuma-Qaq

·

Published

2026-03-02

·

Updated

2026-03-07

·

CVE-2026-24107

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Tenda W20E version 4.0br V15.11.0.6
Description A command injection issue exists in the Tenda W20E router firmware. The firmware does not properly validate the usbPartitionName variable before using it within the doSystemCmd function. This can allow for the execution of arbitrary commands.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the USB partition functionality to minimize the risk of exploitation.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-02499
CVE-2026-24107

Affected Products

Tenda W20E