CVE-2026-24432
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) lack cross-site request forgery (CSRF) protections on administrative endpoints, including those used to change administrator account credentials. As a result, an attacker can craft malicious requests that, when triggered by an authenticated user’s browser, modify administrative passwords and other configuration settings.
Vendor
Product
CWE
Yayın Tarihi
2026-01-26 18:16:40
Güncelleme
2026-01-28 20:11:24
Source Identifier
disclosure@vulncheck.com
KEV Date Added
-