CVE-2026-24436: Tenda W30E V2 Lacks Rate Limiting on Authentication
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) do not enforce rate limiting or account lockout mechanisms on authentication endpoints. This allows attackers to perform unrestricted brute-force attempts against administrative credentials.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24436?
The severity of CVE-2026-24436 is considered high due to its potential for allowing brute-force attacks on the authentication endpoints.
How do I fix CVE-2026-24436?
To fix CVE-2026-24436, update the Tenda W30E V2 firmware to a version that implements rate limiting and account lockout mechanisms.
What type of devices are affected by CVE-2026-24436?
CVE-2026-24436 affects the Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037).
What are the implications of CVE-2026-24436?
The implications of CVE-2026-24436 include unauthorized access to the admin interface due to unrestricted brute-force attempts.
Is there a workaround for CVE-2026-24436?
A temporary workaround for CVE-2026-24436 is to implement additional security measures like changing the default admin credentials or using a VPN.