Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) display stored user account passwords in plaintext within the administrative web interface. Any user with access to the affected management pages can directly view credentials.
History

Mon, 26 Jan 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 26 Jan 2026 18:00:00 +0000

Type Values Removed Values Added
Description Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) display stored user account passwords in plaintext within the administrative web interface. Any user with access to the affected management pages can directly view credentials.
Title Tenda W30E V2 Web UI Reveals Passwords in Cleartext
Weaknesses CWE-317
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-01-26T21:07:38.744Z

Reserved: 2026-01-22T20:23:19.803Z

Link: CVE-2026-24431

cve-icon Vulnrichment

Updated: 2026-01-26T21:07:35.228Z

cve-icon NVD

Status : Received

Published: 2026-01-26T18:16:40.567

Modified: 2026-01-26T18:16:40.567

Link: CVE-2026-24431

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.