CVE-2026-24431
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) display stored user account passwords in plaintext within the administrative web interface. Any user with access to the affected management pages can directly view credentials.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.1
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.20%
- CWE
- CWE-317
- Published
- 2026-01-26
- Last modified
- 2026-05-14
Affected products
- Shenzhen Tenda Technology Co., Ltd. W30E V2
Weakness type
Related vulnerabilities
- CVE-2025-14816 — Information Disclosure, Tampering, and Denial-of-Service Vulnerabilities in GENESIS64, ICONICS Suite, MobileHMI, Hyper Historian, AnalytiX, GENESIS, and MC Works64
- CVE-2026-27516 — Binardat 10G08-0800GSM Network Switch Plaintext Password Exposure
- CVE-2021-34751 — Cisco Firepower Management Center Software Configuration Information Disclosure Vulnerability
- CVE-2021-34750 — Cisco Firepower Management Center Software Configuration Information Disclosure Vulnerability
- CVE-2022-29090 — Dell Wyse Management Suite 3.6.1 and below contains a Sensitive Data Exposure vulnerability. A low...
- CVE-2019-13947 — A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The...