CVE-2026-24433: CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') in Shenzhen Tenda Technology Co., Ltd. W30E V2
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) contain a stored cross-site scripting vulnerability in the user creation functionality. Insufficient input validation allows attacker-controlled script content to be stored and later executed when administrative users access the affected management pages.
AI Analysis
Technical Summary
CVE-2026-24433 is a stored cross-site scripting vulnerability (CWE-79) in Shenzhen Tenda Technology Co., Ltd.'s W30E V2 router firmware up to version V16.01.0.19(5037). The vulnerability occurs due to improper neutralization of input during web page generation in the user creation functionality. An attacker can inject malicious script content that is stored persistently and executed when an administrative user views the affected management interface pages. The CVSS 4.0 vector indicates network attack vector, low attack complexity, no privileges required but user interaction needed, and low impact on confidentiality, integrity, and availability.
Potential Impact
Successful exploitation allows an attacker to execute arbitrary scripts in the context of the administrative interface when an admin accesses the affected pages. This could lead to session hijacking, unauthorized actions, or other impacts typical of stored XSS vulnerabilities. However, the impact is limited by the need for administrative user interaction and the low confidentiality, integrity, and availability impacts as per the CVSS vector.
Mitigation Recommendations
No patch or official fix information is currently available for this vulnerability. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is released, administrators should limit access to the management interface to trusted users and networks and exercise caution when interacting with user-generated content in the management interface.
CVE-2026-24433: CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') in Shenzhen Tenda Technology Co., Ltd. W30E V2
Description
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) contain a stored cross-site scripting vulnerability in the user creation functionality. Insufficient input validation allows attacker-controlled script content to be stored and later executed when administrative users access the affected management pages.
CVSS v4.0
Score 5.1medium
Affected software
Shenzhen Tenda Technology Co., Ltd.
W30E V2
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-24433 is a stored cross-site scripting vulnerability (CWE-79) in Shenzhen Tenda Technology Co., Ltd.'s W30E V2 router firmware up to version V16.01.0.19(5037). The vulnerability occurs due to improper neutralization of input during web page generation in the user creation functionality. An attacker can inject malicious script content that is stored persistently and executed when an administrative user views the affected management interface pages. The CVSS 4.0 vector indicates network attack vector, low attack complexity, no privileges required but user interaction needed, and low impact on confidentiality, integrity, and availability.
Potential Impact
Successful exploitation allows an attacker to execute arbitrary scripts in the context of the administrative interface when an admin accesses the affected pages. This could lead to session hijacking, unauthorized actions, or other impacts typical of stored XSS vulnerabilities. However, the impact is limited by the need for administrative user interaction and the low confidentiality, integrity, and availability impacts as per the CVSS vector.
Mitigation Recommendations
No patch or official fix information is currently available for this vulnerability. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is released, administrators should limit access to the management interface to trusted users and networks and exercise caution when interacting with user-generated content in the management interface.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-01-22T20:23:19.803Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6977a98b4623b1157caf7835
Added to database: 01/26/2026, 17:51:07 UTC
Last enriched: 05/14/2026, 02:10:25 UTC
Last updated: 09/10/2026, 22:18:50 UTC
Views: 218
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.