CVE-2026-24439

Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) fail to include the X-Content-Type-Options: nosniff response header on web management interfaces. As a result, browsers that perform MIME sniffing may incorrectly interpret attacker-influenced responses as executable script.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tenda:w30e_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tenda:w30e:2.0:*:*:*:*:*:*:*

History

17 Jun 2026, 10:23

Type Values Removed Values Added
Summary
  • (es) El firmware de Shenzhen Tenda W30E V2, versiones hasta la V16.01.0.19(5037) inclusive, no incluye el encabezado de respuesta X-Content-Type-Options: nosniff en las interfaces de gestión web. Como resultado, los navegadores que realizan MIME sniffing pueden interpretar incorrectamente las respuestas influenciadas por el atacante como script ejecutable.

28 Jan 2026, 20:01

Type Values Removed Values Added
CPE cpe:2.3:h:tenda:w30e:2.0:*:*:*:*:*:*:*
cpe:2.3:o:tenda:w30e_firmware:*:*:*:*:*:*:*:*
References () https://www.tendacn.com/product/W30E - () https://www.tendacn.com/product/W30E - Product
References () https://www.vulncheck.com/advisories/tenda-w30e-v2-lacks-x-content-type-options-header - () https://www.vulncheck.com/advisories/tenda-w30e-v2-lacks-x-content-type-options-header - Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
First Time Tenda
Tenda w30e Firmware
Tenda w30e

26 Jan 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-26 18:16

Updated : 2026-06-17 10:23


NVD link : CVE-2026-24439

Mitre link : CVE-2026-24439

CVE.ORG link : CVE-2026-24439


JSON object : View

Products Affected

tenda

  • w30e
  • w30e_firmware
CWE
CWE-116

Improper Encoding or Escaping of Output