CVE-2024-52789: High severity tenda w30e firmware vulnerability
Published Nov 19, 2024
·Updated
Tenda W30E v2.0 V16.01.0.8 was discovered to contain a hardcoded password vulnerability in /etcro/shadow, which allows attackers to log in as root.
Affected Software
3 affected components
Tenda W30E
All of the following
Tenda W30e Firmware=16.01.0.8
Tenda W30E=2.0
Event History
Nov 19, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-52789?
CVE-2024-52789 is rated as a critical vulnerability due to the presence of a hardcoded password that allows full root access.
2
How do I fix CVE-2024-52789?
To mitigate CVE-2024-52789, update the firmware of the Tenda W30E to a version that addresses the hardcoded password issue.
3
What types of devices are affected by CVE-2024-52789?
CVE-2024-52789 affects Tenda W30E v2.0 devices running firmware version V16.01.0.8.
4
What are the potential risks of CVE-2024-52789?
The risks of CVE-2024-52789 include unauthorized access to the device and potential compromise of the network.
5
Is there a proof of concept available for CVE-2024-52789?
Yes, there are known proof of concepts that demonstrate exploitability of CVE-2024-52789 due to the hardcoded password.