Description
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) fail to include the X-Content-Type-Options: nosniff response header on web management interfaces. As a result, browsers that perform MIME sniffing may incorrectly interpret attacker-influenced responses as executable script.
Published: 2026-01-26
Score: 2.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Client‑side script execution via MIME sniffing
Action: Apply patch
AI Analysis

Impact

The flaw in the Tenda W30E V2 firmware is that the web management interface fails to set the X-Content-Type-Options: nosniff header. Because browsers perform MIME sniffing when this header is missing, they may interpret crafted responses as executable JavaScript even when the content type is not script. The vulnerability thus allows an attacker who can influence the content served by the router to cause a client’s browser to execute arbitrary script. The impact is limited to the victim who browses the router’s interface, potentially enabling cross‑site scripting or other client‑side code execution.

Affected Systems

This issue affects the Shenzhen Tenda W30E V2 router. Firmware versions up to and including V16.01.0.19(5037) are vulnerable. The flaw exists on the web management pages accessible through the device’s IP address from the local network.

Risk and Exploitability

The CVSS vector gives a base score of 2.1, indicating low severity. The EPSS score is below 1%, meaning the probability of exploitation is very low. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires that a user with a standard browser visits the router’s web UI and that the attacker can inject malicious content into the responses. The lack of the nosniff header facilitates client‑side code execution, but the overall risk remains low because of the limited attack surface and the need for user interaction.

Generated by OpenCVE AI on April 16, 2026 at 17:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the router to the latest firmware version that includes the X-Content-Type-Options header.
  • Restrict access to the router’s web management interface to trusted hosts or enforce it through a VPN or firewall rules.
  • If an upgrade is not immediately possible, place a reverse proxy or content filter in front of the router that injects the X-Content-Type-Options: nosniff header into all responses from the management interface.

Generated by OpenCVE AI on April 16, 2026 at 17:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 28 Jan 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Tenda w30e Firmware
CPEs cpe:2.3:h:tenda:w30e:2.0:*:*:*:*:*:*:*
cpe:2.3:o:tenda:w30e_firmware:*:*:*:*:*:*:*:*
Vendors & Products Tenda w30e Firmware
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Tue, 27 Jan 2026 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Tenda
Tenda w30e
Vendors & Products Tenda
Tenda w30e

Mon, 26 Jan 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 26 Jan 2026 18:00:00 +0000

Type Values Removed Values Added
Description Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) fail to include the X-Content-Type-Options: nosniff response header on web management interfaces. As a result, browsers that perform MIME sniffing may incorrectly interpret attacker-influenced responses as executable script.
Title Tenda W30E V2 Lacks X-Content-Type-Options Header
Weaknesses CWE-116
References
Metrics cvssV4_0

{'score': 2.1, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Tenda W30e W30e Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-03-05T01:30:38.900Z

Reserved: 2026-01-22T20:23:19.803Z

Link: CVE-2026-24439

cve-icon Vulnrichment

Updated: 2026-01-26T19:52:55.821Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-26T18:16:41.463

Modified: 2026-01-28T20:01:46.097

Link: CVE-2026-24439

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T17:45:27Z

Weaknesses