CRITICAL🇵🇱 Wersja polska

CVE-2026-24436

CVSS 9.2v4.0pub. 2026-01-26upd. 2026-01-28

Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) do not enforce rate limiting or account lockout mechanisms on authentication endpoints. This allows attackers to perform unrestricted brute-force attempts against administrative credentials.

🤖 AI Analysis
How it works

The vulnerability results from the lack of rate limiting mechanisms and account lockout on authentication endpoints (CWE-307 — Improper Restriction of Excessive Authentication Attempts). An attacker can send successive login requests without any restrictions, testing different password combinations. The absence of delays, account locks, or CAPTCHA verification allows automated password-cracking tools to operate at full network speed.

Impact

A successful brute-force attack allows an attacker to gain full administrative control over the device, enabling changes to network configuration, interception of network traffic, or use of the router as an entry point to the internal network.

Mitigation & patch

Apply patches available from the manufacturer according to references. As a temporary workaround, it is recommended to restrict access to the administrative panel exclusively to trusted IP addresses and change default credentials to a strong, unique password.

Who is affected

Tenda W30E V2 — firmware versions up to and including V16.01.0.19(5037)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Tenda W30e

    HW
    Tenda
    2.0
  • Tenda W30e Firmware

    OS
    Tenda
    ≤ 16.01.0.19\(5037\)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-38835CRITICAL9.8PL ✓same product

Command injection w Tenda W30E via parametr usbPartitionName

CVE-2026-24429CRITICAL9.3PL ✓same product

Tenda W30E V2 — predefiniowane domyślne hasło w firmware umożliwia nieautoryzowany dostęp

CVE-2025-57085CRITICAL9.8PL ✓same product

Tenda W30E — stack overflow w funkcji UploadCfg (parametr v17)

CVE-2024-32286CRITICAL9.8PL ✓same product

Stack overflow w Tenda W30E przez parametr 'page' w funkcji fromVirtualSer

CVE-2023-49403CRITICAL9.8PL ✓same product

Command injection w routerze Tenda W30E poprzez funkcję setFixTools