Tenda W18E Sensitive Information Disclosure Vulnerability

Vulnerability

A vulnerability allowing sensitive information disclosure has been identified in the Tenda W18E router, specifically in version V16.01.0.8(1625). The issue resides in the web management portal, where an unauthenticated remote attacker can retrieve confidential configuration details. This includes the WiFi SSID, WiFi password, and base64-encoded administrator credentials. The vulnerability is exploited by sending a specially crafted HTTP POST request to the 'getQuickCfgWifiAndLogin' function, which bypasses authentication checks.

Impact

Exploitation of this vulnerability allows for unauthorized access to sensitive configuration information, including WiFi credentials and administrator login details.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
2.5
exploitability
9.1
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
9.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.