PT-2026-4792 · Tenda · Tenda W30E

Kazuma Matsumoto

·

Published

2026-01-26

·

Updated

2026-01-26

·

CVE-2026-24433

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037)
Description The firmware contains a stored cross-site scripting issue in the user creation functionality. Insufficient input validation allows attacker-controlled script content to be stored. This content is then executed when administrative users access the affected management pages.
Recommendations Update to a firmware version later than V16.01.0.19(5037).

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2026-00938
CVE-2026-24433

Affected Products

Tenda W30E