PT-2026-4788 · Tenda · Tenda W30E
Kazuma Matsumoto
·
Published
2026-01-26
·
Updated
2026-01-29
·
CVE-2026-24428
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037)
Description
The firmware contains an authorization flaw within the user management API. A low-privileged authenticated user can alter the administrator account password by submitting a specially crafted request to the backend endpoint. This bypasses role-based access controls enforced by the web interface, potentially granting an attacker full administrative privileges. The vulnerable API endpoint allows unauthorized modification of administrative credentials.
Recommendations
Update firmware to a version later than V16.01.0.19(5037).
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tenda W30E