Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) allow account passwords to be changed through the maintenance interface without requiring verification of the existing password. This enables unauthorized password changes when access to the affected endpoint is obtained.
History

Mon, 26 Jan 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 26 Jan 2026 18:00:00 +0000

Type Values Removed Values Added
Description Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) allow account passwords to be changed through the maintenance interface without requiring verification of the existing password. This enables unauthorized password changes when access to the affected endpoint is obtained.
Title Tenda W30E V2 Allows Password Changes Without Verifying Current Password
Weaknesses CWE-620
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-01-26T18:59:15.816Z

Reserved: 2026-01-22T20:23:19.804Z

Link: CVE-2026-24440

cve-icon Vulnrichment

Updated: 2026-01-26T18:59:09.274Z

cve-icon NVD

Status : Received

Published: 2026-01-26T18:16:41.637

Modified: 2026-01-26T18:16:41.637

Link: CVE-2026-24440

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.