CVE-2026-24437: CWE-525 Use of Web Browser Cache Containing Sensitive Information in Shenzhen Tenda Technology Co., Ltd. W30E V2
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) serve sensitive administrative content without appropriate cache-control directives. As a result, browsers may store credential-bearing responses locally, exposing them to subsequent unauthorized access.
AI Analysis
Technical Summary
CVE-2026-24437 affects Shenzhen Tenda Technology Co., Ltd.'s W30E V2 router firmware versions up to V16.01.0.19(5037). The vulnerability arises because the device serves sensitive administrative content without proper cache-control directives, causing browsers to cache credential-bearing responses. This can lead to unauthorized access if an attacker gains access to the local browser cache. The CVSS 4.0 vector indicates a local attacker with low privileges can exploit this without user interaction, but the impact is limited to confidentiality due to exposure of cached sensitive data. There is no indication of remote exploitation or integrity/availability impact.
Potential Impact
The vulnerability exposes sensitive administrative credentials stored in the browser cache, which could be accessed by unauthorized users with local access to the affected machine. This may lead to unauthorized administrative access to the device if cached credentials are reused. The impact is limited to confidentiality compromise of cached data. There are no known exploits in the wild, and no evidence of remote exploitation capability.
Mitigation Recommendations
No official patch or remediation is currently available for this vulnerability. Users should check Shenzhen Tenda Technology Co., Ltd. advisories for updates. As a temporary mitigation, users should clear their browser cache regularly and avoid accessing the administrative interface from shared or untrusted devices. Network administrators should restrict local access to trusted users only. Monitor vendor communications for any forthcoming fixes.
CVE-2026-24437: CWE-525 Use of Web Browser Cache Containing Sensitive Information in Shenzhen Tenda Technology Co., Ltd. W30E V2
Description
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) serve sensitive administrative content without appropriate cache-control directives. As a result, browsers may store credential-bearing responses locally, exposing them to subsequent unauthorized access.
CVSS v4.0
Score 4.8medium
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-24437 affects Shenzhen Tenda Technology Co., Ltd.'s W30E V2 router firmware versions up to V16.01.0.19(5037). The vulnerability arises because the device serves sensitive administrative content without proper cache-control directives, causing browsers to cache credential-bearing responses. This can lead to unauthorized access if an attacker gains access to the local browser cache. The CVSS 4.0 vector indicates a local attacker with low privileges can exploit this without user interaction, but the impact is limited to confidentiality due to exposure of cached sensitive data. There is no indication of remote exploitation or integrity/availability impact.
Potential Impact
The vulnerability exposes sensitive administrative credentials stored in the browser cache, which could be accessed by unauthorized users with local access to the affected machine. This may lead to unauthorized administrative access to the device if cached credentials are reused. The impact is limited to confidentiality compromise of cached data. There are no known exploits in the wild, and no evidence of remote exploitation capability.
Mitigation Recommendations
No official patch or remediation is currently available for this vulnerability. Users should check Shenzhen Tenda Technology Co., Ltd. advisories for updates. As a temporary mitigation, users should clear their browser cache regularly and avoid accessing the administrative interface from shared or untrusted devices. Network administrators should restrict local access to trusted users only. Monitor vendor communications for any forthcoming fixes.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-01-22T20:23:19.803Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6977a98b4623b1157caf783d
Added to database: 01/26/2026, 17:51:07 UTC
Last enriched: 05/14/2026, 02:10:51 UTC
Last updated: 09/10/2026, 19:36:53 UTC
Views: 227
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.