CVE-2026-24432: Tenda W30E V2 Missing CSRF Protections for Administrative Actions
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) lack cross-site request forgery (CSRF) protections on administrative endpoints, including those used to change administrator account credentials. As a result, an attacker can craft malicious requests that, when triggered by an authenticated user’s browser, modify administrative passwords and other configuration settings.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24432?
CVE-2026-24432 is classified as a high severity vulnerability due to the lack of CSRF protections on administrative endpoints.
How do I fix CVE-2026-24432?
To remediate CVE-2026-24432, update the Tenda W30E V2 firmware to a version released after V16.01.0.19(5037) that includes CSRF protections.
What are the risks associated with CVE-2026-24432?
The risks of CVE-2026-24432 include unauthorized changes to administrator credentials and other sensitive configurations.
Which devices are affected by CVE-2026-24432?
CVE-2026-24432 affects Tenda W30E V2 devices running firmware versions up to and including V16.01.0.19(5037).
What type of attack does CVE-2026-24432 enable?
CVE-2026-24432 enables cross-site request forgery (CSRF) attacks on administrative actions, potentially compromising device security.