PT-2026-4793 · Tenda · Tenda W30E
CVSS v2.0
10
Crítica
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037)
Description
The firmware does not implement rate limiting or account lockout features on authentication endpoints. This allows attackers to attempt unrestricted brute-force attacks against administrative credentials. The affected device is used in home and small office networks.
Recommendations
Update to a firmware version newer than V16.01.0.19(5037).
Correção
Improper Restriction of Excessive Authentication Attempts
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Tenda W30E