CVE-2026-30140: High severity Tenda W15E vulnerability
An incorrect access control vulnerability exists in Tenda W15E V02.03.01.26cn. An unauthenticated attacker can access the /cgi-bin/DownloadCfg/RouterCfm.jpg endpoint to download the configuration file containing plaintext administrator credentials, leading to sensitive information disclosure and potential remote administrative access.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-30140?
CVE-2026-30140 has a high severity due to its potential for sensitive information disclosure.
How do I fix CVE-2026-30140?
To fix CVE-2026-30140, update the Tenda W15E firmware to the latest version to correct the access control vulnerability.
What types of attacks can exploit CVE-2026-30140?
CVE-2026-30140 can be exploited by unauthenticated attackers who can access the router's configuration file.
What information is exposed by CVE-2026-30140?
CVE-2026-30140 exposes plaintext administrator credentials through the accessible configuration file.
Which devices are affected by CVE-2026-30140?
Devices affected by CVE-2026-30140 include the Tenda W15E running firmware version 02.03.01.26_cn.