CVE-2026-24439: Tenda W30E V2 Lacks X-Content-Type-Options Header
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) fail to include the X-Content-Type-Options: nosniff response header on web management interfaces. As a result, browsers that perform MIME sniffing may incorrectly interpret attacker-influenced responses as executable script.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24439?
CVE-2026-24439 has a medium severity rating due to the lack of security headers that could expose users to content type vulnerabilities.
How do I fix CVE-2026-24439?
To fix CVE-2026-24439, update the Tenda W30E V2 firmware to a version that includes the X-Content-Type-Options header.
What is the impact of CVE-2026-24439 on Tenda W30E V2?
The impact of CVE-2026-24439 on Tenda W30E V2 is that users may be at risk of cross-browser issues arising from unprotected MIME types.
Which versions of Tenda W30E V2 are affected by CVE-2026-24439?
Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) are affected by CVE-2026-24439.
Is there a workaround for CVE-2026-24439?
Currently, there are no specific workarounds for CVE-2026-24439, and updating the firmware is recommended.