Authentication Bypass Vulnerability in Tenda W18E Router
CVE-2024-46434

8.8HIGH

Key Information:

Vendor
Tenda
Vendor
CVE Published:
10 February 2025

Summary

The Tenda W18E Router has a vulnerability in its web management portal that permits unauthorized remote attackers to bypass authentication measures. By sending a specially crafted HTTP request, an attacker can gain administrative access to the device, potentially compromising network security and user privacy. This flaw underscores the importance of robust security protocols in network devices, highlighting the need for users to apply updates and safeguards to mitigate potential threats.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.