Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) do not enforce rate limiting or account lockout mechanisms on authentication endpoints. This allows attackers to perform unrestricted brute-force attempts against administrative credentials.
The vulnerability results from the lack of rate limiting mechanisms and account lockout on authentication endpoints (CWE-307 — Improper Restriction of Excessive Authentication Attempts). An attacker can send successive login requests without any restrictions, testing different password combinations. The absence of delays, account locks, or CAPTCHA verification allows automated password-cracking tools to operate at full network speed.
A successful brute-force attack allows an attacker to gain full administrative control over the device, enabling changes to network configuration, interception of network traffic, or use of the router as an entry point to the internal network.
Apply patches available from the manufacturer according to references. As a temporary workaround, it is recommended to restrict access to the administrative panel exclusively to trusted IP addresses and change default credentials to a strong, unique password.
Tenda W30E V2 — firmware versions up to and including V16.01.0.19(5037)
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XTenda W30e
HWTenda2.0Tenda W30e Firmware
OSTenda≤ 16.01.0.19\(5037\)
Related vulnerabilities
Command injection w Tenda W30E via parametr usbPartitionName
Tenda W30E V2 — predefiniowane domyślne hasło w firmware umożliwia nieautoryzowany dostęp
Tenda W30E — stack overflow w funkcji UploadCfg (parametr v17)
Stack overflow w Tenda W30E przez parametr 'page' w funkcji fromVirtualSer
Command injection w routerze Tenda W30E poprzez funkcję setFixTools