CVE-2026-24437: Tenda W30E V2 Missing Cache Controls for Credential-bearing Pages
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) serve sensitive administrative content without appropriate cache-control directives. As a result, browsers may store credential-bearing responses locally, exposing them to subsequent unauthorized access.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24437?
CVE-2026-24437 has a medium severity rating due to the risk of sensitive data exposure.
How do I fix CVE-2026-24437?
To fix CVE-2026-24437, update the Tenda W30E V2 firmware to the latest version that includes appropriate cache-control directives.
What vulnerabilities are associated with CVE-2026-24437?
CVE-2026-24437 is associated with the risk of browsers storing sensitive administrative content due to missing cache-control headers.
What devices are affected by CVE-2026-24437?
CVE-2026-24437 specifically affects Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037).
What are the potential impacts of CVE-2026-24437?
The potential impacts of CVE-2026-24437 include unauthorized access to sensitive information if cached responses are retrieved by unauthorized users.