Description
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) allow account passwords to be changed through the maintenance interface without requiring verification of the existing password. This enables unauthorized password changes when access to the affected endpoint is obtained.
Published: 2026-01-26
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized account takeover via password change
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows an attacker who has reached the maintenance interface of the Tenda W30E V2 router to change an account password without first providing the existing password. This omission of credential verification enables the attacker to replace legitimate passwords, effectively taking control of an account or locking out the original user. The weakness is a classic instance of improper credential verification (CWE‑620) and could be used to subvert administrative access, disrupt services, or facilitate further attacks against the network.

Affected Systems

Shenzhen Tenda Technology Co., Ltd. routers, specifically the W30E V2 model with firmware versions up to V16.01.0.19(5037). Only firmware versions prior to this are affected; newer releases are presumed to have fixed the issue.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity, while the EPSS score of less than 1 % suggests the likelihood of exploitation is currently low. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote or local access to the device’s maintenance web interface, where an authorised user normally changes passwords; attackers could exploit an unauthenticated or session‑hijacked connection to perform the change without authentication. The risk is elevated for devices exposed to wide networks or with weak default credentials.

Generated by OpenCVE AI on April 16, 2026 at 17:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the device firmware to the latest available version that enforces current password verification before allowing changes.
  • Restrict access to the maintenance interface by configuring firewall rules, VPN access, or disabling remote management features on the router.
  • Change the default administrative credentials immediately and enforce strong, unique passwords for all accounts.

Generated by OpenCVE AI on April 16, 2026 at 17:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 28 Jan 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Tenda w30e Firmware
CPEs cpe:2.3:h:tenda:w30e:2.0:*:*:*:*:*:*:*
cpe:2.3:o:tenda:w30e_firmware:*:*:*:*:*:*:*:*
Vendors & Products Tenda w30e Firmware
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Tue, 27 Jan 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Tenda
Tenda w30e
Vendors & Products Tenda
Tenda w30e

Mon, 26 Jan 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 26 Jan 2026 18:00:00 +0000

Type Values Removed Values Added
Description Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) allow account passwords to be changed through the maintenance interface without requiring verification of the existing password. This enables unauthorized password changes when access to the affected endpoint is obtained.
Title Tenda W30E V2 Allows Password Changes Without Verifying Current Password
Weaknesses CWE-620
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Tenda W30e W30e Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-03-05T01:30:39.967Z

Reserved: 2026-01-22T20:23:19.804Z

Link: CVE-2026-24440

cve-icon Vulnrichment

Updated: 2026-01-26T18:59:09.274Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-26T18:16:41.637

Modified: 2026-01-28T19:20:05.660

Link: CVE-2026-24440

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T17:45:27Z

Weaknesses