Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Tenda W30E V2 Missing CSRF Protections for Administrative Actions
Vulnerability Description
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) lack cross-site request forgery (CSRF) protections on administrative endpoints, including those used to change administrator account credentials. As a result, an attacker can craft malicious requests that, when triggered by an authenticated user’s browser, modify administrative passwords and other configuration settings.
CVSS Information
N/A
Vulnerability Type
跨站请求伪造(CSRF)
Vulnerability Title
Tenda W30E 跨站请求伪造漏洞
Vulnerability Description
Tenda W30E是中国腾达(Tenda)公司的一款路由器。 Tenda W30E V2 V16.01.0.19(5037)及之前版本存在跨站请求伪造漏洞,该漏洞源于管理端点缺少跨站请求伪造保护,可能导致攻击者修改管理员密码。
CVSS Information
N/A
Vulnerability Type
N/A