CVE-2026-24431 Details
Description
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) display stored user account passwords in plaintext within the administrative web interface. Any user with access to the affected management pages can directly view credentials.
A vulnerability exists in the Shenzhen Tenda W30E V2 router, specifically in firmware versions through V16.01.0.19(5037). This vulnerability allows stored user account passwords to be displayed in plaintext within the administrative web interface. Any user with access to the affected management pages can directly view these credentials.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-317 | Cleartext Storage of Sensitive Information in GUI | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| tenda w30e firmware | <= 16.01.0.19\(5037\) |
CPE
Remediation
| |
| tenda w30e | 2.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 28, 2026 | Initial Analysis | [email protected] |
| Jan 26, 2026 | New CVE Received | [email protected] |