Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) serve sensitive administrative content without appropriate cache-control directives. As a result, browsers may store credential-bearing responses locally, exposing them to subsequent unauthorized access.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 26 Jan 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 26 Jan 2026 18:00:00 +0000

Type Values Removed Values Added
Description Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) serve sensitive administrative content without appropriate cache-control directives. As a result, browsers may store credential-bearing responses locally, exposing them to subsequent unauthorized access.
Title Tenda W30E V2 Missing Cache Controls for Credential-bearing Pages
Weaknesses CWE-525
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-01-26T21:06:52.660Z

Reserved: 2026-01-22T20:23:19.803Z

Link: CVE-2026-24437

cve-icon Vulnrichment

Updated: 2026-01-26T21:06:46.201Z

cve-icon NVD

Status : Received

Published: 2026-01-26T18:16:41.317

Modified: 2026-01-26T18:16:41.317

Link: CVE-2026-24437

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses