CVE-2026-24440: Tenda W30E V2 Allows Password Changes Without Verifying Current Password
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) allow account passwords to be changed through the maintenance interface without requiring verification of the existing password. This enables unauthorized password changes when access to the affected endpoint is obtained.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24440?
CVE-2026-24440 is considered a high severity vulnerability due to the potential for unauthorized password changes.
How do I fix CVE-2026-24440?
To fix CVE-2026-24440, update the Tenda W30E V2 firmware to a version later than V16.01.0.19(5037) that addresses this issue.
What are the risks associated with CVE-2026-24440?
The risks of CVE-2026-24440 include unauthorized access to the device, allowing malicious users to change passwords and potentially lock out legitimate users.
What devices are affected by CVE-2026-24440?
CVE-2026-24440 affects the Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037).
Where can I report a vulnerability like CVE-2026-24440?
Vulnerabilities like CVE-2026-24440 can be reported directly to the vendor, Tenda, or through a dedicated security vulnerability reporting platform.