Description
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) ship with a predefined default password for a built-in authentication account that is not required to be changed during initial configuration. An attacker can leverage these default credentials to gain authenticated access to the management interface.
Published: 2026-01-26
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Authenticated Access to Management Interface
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from the Tenda W30E V2 firmware embedding a hardcoded default password for a built‑in authentication account that is not required to be changed during initial configuration. This flaw allows an attacker to log in with the supplied default credentials, thereby gaining authenticated access to the router's management interface. The impact is classic credential misuse, enabling an attacker to alter device settings, monitor traffic, or use the device as part of a larger attack chain. This weakness maps to CWE-1393, identifying it as a hardcoded or default credential issue.

Affected Systems

The affected device is the Shenzhen Tenda Technology Co., Ltd. W30E V2 router. Firmware versions up to and including V16.01.0.19(5037) contain the hardcoded default password. No other manufacturers or product lines are listed as affected.

Risk and Exploitability

The CVSS v3.1 score of 9.3 indicates critical severity. Despite the extremely low EPSS (<1%), the threat remains high because an attacker only needs to know or guess a single known credential pair to gain privileged access. The likely attack vector is remote access to the router's web‑based management interface over the LAN or WAN, which many home and small‑office networks expose. Because this shortcut removes the need for credential discovery or exploitation of other software, remediation is crucial even if actual exploitation probabilities are low.

Generated by OpenCVE AI on April 16, 2026 at 17:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Log in using the default credentials for the built‑in account and immediately change the password to a strong, unique account password.
  • Upgrade the router to the latest firmware version released by Shenzhen Tenda that removes or requires password change for the built‑in account.
  • If an up‑to‑date firmware is unavailable, disable the built‑in account entirely or restrict the management interface to trusted local IP addresses and block remote management ports from the internet.

Generated by OpenCVE AI on April 16, 2026 at 17:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 29 Jan 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Tenda w30e Firmware
CPEs cpe:2.3:h:tenda:w30e:-:*:*:*:*:*:*:*
cpe:2.3:o:tenda:w30e_firmware:*:*:*:*:*:*:*:*
Vendors & Products Tenda w30e Firmware
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Tue, 27 Jan 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Tenda
Tenda w30e
Vendors & Products Tenda
Tenda w30e

Mon, 26 Jan 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 26 Jan 2026 18:00:00 +0000

Type Values Removed Values Added
Description Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) ship with a predefined default password for a built-in authentication account that is not required to be changed during initial configuration. An attacker can leverage these default credentials to gain authenticated access to the management interface.
Title Tenda W30E V2 Hardcoded Default Password for Built-in Account
Weaknesses CWE-1393
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Tenda W30e W30e Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-03-05T01:30:31.144Z

Reserved: 2026-01-22T20:23:19.802Z

Link: CVE-2026-24429

cve-icon Vulnrichment

Updated: 2026-01-26T18:57:07.554Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-26T18:16:40.267

Modified: 2026-01-29T13:01:22.300

Link: CVE-2026-24429

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T17:45:27Z

Weaknesses