CVE-2024-46429

A hardcoded credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access the web management portal using a default guest account with administrative privileges.
References
Link Resource
https://reddassolutions.com/blog/tenda_w18e_security_research Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tenda:w18e_firmware:16.01.0.8\(1625\):*:*:*:*:*:*:*
cpe:2.3:h:tenda:w18e:-:*:*:*:*:*:*:*

History

28 Mar 2025, 18:21

Type Values Removed Values Added
References () https://reddassolutions.com/blog/tenda_w18e_security_research - () https://reddassolutions.com/blog/tenda_w18e_security_research - Exploit, Third Party Advisory
CPE cpe:2.3:h:tenda:w18e:-:*:*:*:*:*:*:*
cpe:2.3:o:tenda:w18e_firmware:16.01.0.8\(1625\):*:*:*:*:*:*:*
Summary
  • (es) Una vulnerabilidad de credenciales codificadas en Tenda W18E V16.01.0.8(1625) permite a atacantes remotos no autenticados acceder al portal de administración web utilizando una cuenta de invitado predeterminada con privilegios administrativos.
First Time Tenda w18e Firmware
Tenda
Tenda w18e

10 Feb 2025, 22:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 8.0
v2 : unknown
v3 : 8.8

10 Feb 2025, 21:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.0
CWE CWE-798

10 Feb 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-10 19:15

Updated : 2025-03-28 18:21


NVD link : CVE-2024-46429

Mitre link : CVE-2024-46429

CVE.ORG link : CVE-2024-46429


JSON object : View

Products Affected

tenda

  • w18e
  • w18e_firmware
CWE
CWE-798

Use of Hard-coded Credentials