CVE Tools

W30E Firmware

63 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for W30E Firmware, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.

W30E Firmware CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
W30E Firmware CVEs per month
MonthCVEs
2024-100
2024-111
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-093
2025-100
2025-110
2025-120
2026-0111
2026-020
2026-030
2026-042
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 63 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical1829%
  • High3556%
  • Medium1016%

Latest CVEs

The 15 most recently published vulnerabilities affecting W30E Firmware.

  1. CVE-2026-38835Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the formSetUSBPartitionUmount function via the usbPartitionName parameter. This vulnerability allows attackers ...9.8
  2. CVE-2026-38834Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the do_ping_action function via the hostName parameter. This vulnerability allows attackers to execute arbitrar...7.3
  3. CVE-2026-24435Tenda W30E V2 Permissive CORS Allows Cross-origin Data Access6.5
  4. CVE-2026-24439Tenda W30E V2 Lacks X-Content-Type-Options Header6.5
  5. CVE-2026-24432Tenda W30E V2 Missing CSRF Protections for Administrative Actions4.3
  6. CVE-2026-24433Tenda W30E V2 Stored XSS via Username Field5.4
  7. CVE-2026-24431Tenda W30E V2 Web UI Reveals Passwords in Cleartext6.5
  8. CVE-2026-24437Tenda W30E V2 Missing Cache Controls for Credential-bearing Pages5.5
  9. CVE-2026-24436Tenda W30E V2 Lacks Rate Limiting on Authentication9.8
  10. CVE-2026-24428Tenda W30E V2 Incorrect Authorization Allows Administrator Password Change8.8
  11. CVE-2026-24430Tenda W30E V2 HTTP Responses Expose Plaintext Credentials7.5
  12. CVE-2026-24429Tenda W30E V2 Hardcoded Default Password for Built-in Account9.8
  13. CVE-2026-24440Tenda W30E V2 Allows Password Changes Without Verifying Current Password8.8
  14. CVE-2025-57087Tenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the countryCode parameter in the werlessAdvancedSet function. This vulnerability allows attackers to cause a Denial of Se...7.5
  15. CVE-2025-57085Tenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the v17 parameter in the UploadCfg function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a...9.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store