CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 4.3. Exploitation may require the attacker to be authenticated.
CVE
CVE-2026-24432
Severity
MEDIUM
CVSS
4.3
EPSS
0.11%
Original NVD Description
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) lack cross-site request forgery (CSRF) protections on administrative endpoints, including those used to change administrator account credentials. As a result, an attacker can craft malicious requests that, when triggered by an authenticated user’s browser, modify administrative passwords and other configuration settings.
Related CVEs
Other vulnerabilities affecting the same vendor(s)