CVE-2026-24433: Tenda W30E V2 Stored XSS via Username Field
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) contain a stored cross-site scripting vulnerability in the user creation functionality. Insufficient input validation allows attacker-controlled script content to be stored and later executed when administrative users access the affected management pages.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24433?
CVE-2026-24433 is classified as a high severity vulnerability due to its potential for stored cross-site scripting attacks.
How do I fix CVE-2026-24433?
To mitigate CVE-2026-24433, update the Tenda W30E V2 firmware to a version beyond V16.01.0.19(5037) where the vulnerability is patched.
What is the impact of CVE-2026-24433?
The impact of CVE-2026-24433 includes the potential for attackers to execute malicious scripts in the context of authenticated users.
Which versions of the Tenda W30E V2 are affected by CVE-2026-24433?
Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) are affected by CVE-2026-24433.
Who can exploit CVE-2026-24433?
CVE-2026-24433 can be exploited by any authenticated attacker who can access the user creation functionality in the affected Tenda W30E V2 devices.