CVE-2026-24432
Tenda W30E V2 Missing CSRF Protections for Administrative Actions
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 5.1EPSS 0.1%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
26 ene 2026Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) lack cross-site request forgery (CSRF) protections on administrative endpoints, including those used to change administrator account credentials. As a result, an attacker can craft malicious requests that, when triggered by an authenticated user’s browser, modify administrative passwords and other configuration settings.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Productos afectados
Shenzhen Tenda Technology Co., Ltd. · W30E V2¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →