Shenzhen Tenda W30E V2
cpe:2.3:h:tenda:w30e:*:*:*:*:*:*:*, +1 more
- <= v16.01.0.19(5037)
A vulnerability exists in the Tenda W30E V2 router, specifically in firmware versions up to and including V16.01.0.19(5037). The issue arises from an insecure Cross-Origin Resource Sharing (CORS) policy implemented on authenticated administrative endpoints. The router allows any origin to make credentialed cross-origin requests, which could be exploited by attackers.
Exploitation of this vulnerability could lead to unauthorized access to sensitive data or functionality on the router's administrative interface, by allowing attacker-controlled origins to send requests that include credentials.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.