First published: Tue Nov 19 2024(Updated: )
Tenda W30E v2.0 V16.01.0.8 was discovered to contain a hardcoded password vulnerability in /etc_ro/shadow, which allows attackers to log in as root.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tenda W30e Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-52789 is rated as a critical vulnerability due to the presence of a hardcoded password that allows full root access.
To mitigate CVE-2024-52789, update the firmware of the Tenda W30E to a version that addresses the hardcoded password issue.
CVE-2024-52789 affects Tenda W30E v2.0 devices running firmware version V16.01.0.8.
The risks of CVE-2024-52789 include unauthorized access to the device and potential compromise of the network.
Yes, there are known proof of concepts that demonstrate exploitability of CVE-2024-52789 due to the hardcoded password.