CRITICAL🇵🇱 Wersja polska

CVE-2026-24429

CVSS 9.3v4.0pub. 2026-01-26upd. 2026-01-29

Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) ship with a predefined default password for a built-in authentication account that is not required to be changed during initial configuration. An attacker can leverage these default credentials to gain authenticated access to the management interface.

🤖 AI Analysis
How it works

The manufacturer embedded a predefined, known default password in the firmware assigned to a built-in administrative account. The device does not enforce changing this password during initial startup or configuration. An attacker, knowing the default login credentials, can directly authenticate to the management interface over the network without needing to obtain any information or interact with the user.

Impact

An attacker gains authenticated access to the device management interface, which allows them to completely reconfigure the router, intercept network traffic, and potentially use the device as an entry point into a protected network.

Mitigation & patch

The default password on the device management interface should be immediately changed to a unique and strong password. Access to the management interface should also be restricted exclusively to trusted IP addresses or network segments. It is recommended to check for updated firmware availability from the manufacturer at https://www.tendacn.com/product/W30E and implement it immediately if available.

Who is affected

Tenda W30E V2 — firmware versions up to and including V16.01.0.19(5037)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Tenda W30e

    HW
    Tenda
    all versions
  • Tenda W30e Firmware

    OS
    Tenda
    ≤ 16.01.0.19\(5037\)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-38835CRITICAL9.8PL ✓same product

Command injection w Tenda W30E via parametr usbPartitionName

CVE-2026-24436CRITICAL9.2PL ✓same product

Brak ograniczenia prób logowania w Tenda W30E — atak brute-force

CVE-2025-57085CRITICAL9.8PL ✓same product

Tenda W30E — stack overflow w funkcji UploadCfg (parametr v17)

CVE-2024-32286CRITICAL9.8PL ✓same product

Stack overflow w Tenda W30E przez parametr 'page' w funkcji fromVirtualSer

CVE-2023-49403CRITICAL9.8PL ✓same product

Command injection w routerze Tenda W30E poprzez funkcję setFixTools