CVE-2026-24429: Tenda W30E V2 Hardcoded Default Password for Built-in Account
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) ship with a predefined default password for a built-in authentication account that is not required to be changed during initial configuration. An attacker can leverage these default credentials to gain authenticated access to the management interface.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24429?
CVE-2026-24429 is classified as a high severity vulnerability due to the risk of unauthorized access.
How do I fix CVE-2026-24429?
To fix CVE-2026-24429, change the default password for the built-in account immediately after installation.
What devices are affected by CVE-2026-24429?
CVE-2026-24429 affects Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037).
What is the nature of CVE-2026-24429?
CVE-2026-24429 involves a hardcoded default password for a built-in authentication account that is not required to be changed.
Can CVE-2026-24429 be exploited remotely?
Yes, CVE-2026-24429 can be exploited remotely if the default password is not changed.