CVE-2026-24437
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2026-01-26

Last updated on: 2026-01-28

Assigner: VulnCheck

Description
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) serve sensitive administrative content without appropriate cache-control directives. As a result, browsers may store credential-bearing responses locally, exposing them to subsequent unauthorized access.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-01-26
Last Modified
2026-01-28
Generated
2026-06-16
AI Q&A
2026-01-26
EPSS Evaluated
2026-06-15
NVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
tenda w30e_firmware to 16.01.0.19\(5037\) (inc)
tenda w30e 2.0
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-525 The web application does not use an appropriate caching policy that specifies the extent to which each web page and associated form fields should be cached.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Impact Analysis

If exploited, this vulnerability can lead to unauthorized access to sensitive administrative credentials stored in the browser cache. An attacker with local access to the device or browser cache could retrieve these credentials, potentially compromising the router's administrative functions. [1]

Executive Summary

This vulnerability affects the Tenda W30E V2 router firmware versions up to and including V16.01.0.19(5037). The firmware serves sensitive administrative pages without proper cache-control headers, causing browsers to locally store credential-bearing responses. This can allow unauthorized access to sensitive information if an attacker accesses the cached data. [1]

Detection Guidance

You can detect this vulnerability by checking if the Tenda W30E V2 router firmware serves sensitive administrative pages without proper cache-control headers. One approach is to use a tool like curl to inspect the HTTP response headers from the router's administrative interface. For example, run the command: curl -I http://<router-ip>/admin or the specific URL serving administrative content, and check if the 'Cache-Control' header is missing or does not prevent caching (e.g., missing 'no-store' or 'no-cache' directives). If credential-bearing pages lack appropriate cache-control headers, the device is vulnerable. [1]

Mitigation Strategies

Immediate mitigation steps include avoiding access to the router's administrative interface from untrusted devices or networks, clearing browser caches regularly to remove any stored credential-bearing pages, and restricting local access to the device. Additionally, monitor for firmware updates from Tenda that address this issue and apply them as soon as they become available. [1]

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-24437. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart