CVE-2024-46434

Tenda W18E V16.01.0.8(1625) suffers from authentication bypass in the web management portal allowing an unauthorized remote attacker to gain administrative access by sending a specially crafted HTTP request.
References
Link Resource
https://reddassolutions.com/blog/tenda_w18e_security_research Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tenda:w18e_firmware:16.01.0.8\(1625\):*:*:*:*:*:*:*
cpe:2.3:h:tenda:w18e:-:*:*:*:*:*:*:*

History

25 Mar 2025, 18:13

Type Values Removed Values Added
First Time Tenda w18e Firmware
Tenda
Tenda w18e
References () https://reddassolutions.com/blog/tenda_w18e_security_research - () https://reddassolutions.com/blog/tenda_w18e_security_research - Exploit, Third Party Advisory
CPE cpe:2.3:h:tenda:w18e:-:*:*:*:*:*:*:*
cpe:2.3:o:tenda:w18e_firmware:16.01.0.8\(1625\):*:*:*:*:*:*:*
Summary
  • (es) Tenda W18E V16.01.0.8(1625) sufre una evasión de autenticación en el portal de administración web, lo que permite que un atacante remoto no autorizado obtenga acceso administrativo mediante el envío de una solicitud HTTP especialmente manipulada.

10 Feb 2025, 22:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.3
v2 : unknown
v3 : 8.8

10 Feb 2025, 21:15

Type Values Removed Values Added
CWE CWE-287
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.3

10 Feb 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-10 19:15

Updated : 2025-03-25 18:13


NVD link : CVE-2024-46434

Mitre link : CVE-2024-46434

CVE.ORG link : CVE-2024-46434


JSON object : View

Products Affected

tenda

  • w18e
  • w18e_firmware
CWE
CWE-287

Improper Authentication