CVE-2026-24436: CWE-307 Improper Restriction of Excessive Authentication Attempts in Shenzhen Tenda Technology Co., Ltd. W30E V2
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) do not enforce rate limiting or account lockout mechanisms on authentication endpoints. This allows attackers to perform unrestricted brute-force attempts against administrative credentials.
AI Analysis
Technical Summary
CVE-2026-24436 describes an improper restriction of excessive authentication attempts in Shenzhen Tenda Technology Co., Ltd.'s W30E V2 router firmware versions up to V16.01.0.19(5037). The firmware does not implement rate limiting or account lockout mechanisms on its authentication endpoints, allowing an unauthenticated attacker to perform unlimited brute-force attempts to guess administrative credentials. This vulnerability has a critical severity rating with a CVSS 4.0 score of 9.2, indicating high impact and exploitability. No patch or official fix has been documented, and no known exploits have been reported.
Potential Impact
Successful exploitation could allow an attacker to gain unauthorized administrative access to the affected device by brute forcing credentials without restriction. This could lead to full control over the device, potentially compromising network security and device functionality. The lack of rate limiting significantly increases the risk of credential compromise.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, it is recommended to restrict network access to the device's administrative interface, use strong and unique passwords, and monitor for suspicious login attempts. Avoid exposing the device's management interface to untrusted networks.
CVE-2026-24436: CWE-307 Improper Restriction of Excessive Authentication Attempts in Shenzhen Tenda Technology Co., Ltd. W30E V2
Description
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) do not enforce rate limiting or account lockout mechanisms on authentication endpoints. This allows attackers to perform unrestricted brute-force attempts against administrative credentials.
CVSS v4.0
Score 9.2critical
Affected software
Shenzhen Tenda Technology Co., Ltd.
W30E V2
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-24436 describes an improper restriction of excessive authentication attempts in Shenzhen Tenda Technology Co., Ltd.'s W30E V2 router firmware versions up to V16.01.0.19(5037). The firmware does not implement rate limiting or account lockout mechanisms on its authentication endpoints, allowing an unauthenticated attacker to perform unlimited brute-force attempts to guess administrative credentials. This vulnerability has a critical severity rating with a CVSS 4.0 score of 9.2, indicating high impact and exploitability. No patch or official fix has been documented, and no known exploits have been reported.
Potential Impact
Successful exploitation could allow an attacker to gain unauthorized administrative access to the affected device by brute forcing credentials without restriction. This could lead to full control over the device, potentially compromising network security and device functionality. The lack of rate limiting significantly increases the risk of credential compromise.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, it is recommended to restrict network access to the device's administrative interface, use strong and unique passwords, and monitor for suspicious login attempts. Avoid exposing the device's management interface to untrusted networks.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-01-22T20:23:19.803Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6977a98b4623b1157caf7839
Added to database: 01/26/2026, 17:51:07 UTC
Last enriched: 05/14/2026, 02:10:40 UTC
Last updated: 09/10/2026, 22:18:51 UTC
Views: 272
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.