CVE Vulnerabilities

CVE-2026-24431

Cleartext Storage of Sensitive Information in GUI

Published: Jan 26, 2026 | Modified: Jan 28, 2026
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) display stored user account passwords in plaintext within the administrative web interface. Any user with access to the affected management pages can directly view credentials.

Weakness

The product stores sensitive information in cleartext within the GUI.

Affected Software

NameVendorStart VersionEnd Version
W30e_firmwareTenda*16.01.0.19(5037) (including)

References