PT-2026-4793 · Tenda · Tenda W30E

·

CVE-2026-24436

·

Publicado

2026-01-26

·

Atualizado

2026-01-26

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037)
Description The firmware does not implement rate limiting or account lockout features on authentication endpoints. This allows attackers to attempt unrestricted brute-force attacks against administrative credentials. The affected device is used in home and small office networks.
Recommendations Update to a firmware version newer than V16.01.0.19(5037).

Correção

Improper Restriction of Excessive Authentication Attempts

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-00937
CVE-2026-24436

Produtos afetados

Tenda W30E