Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Tenda W30E V2 Lacks X-Content-Type-Options Header
Vulnerability Description
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) fail to include the X-Content-Type-Options: nosniff response header on web management interfaces. As a result, browsers that perform MIME sniffing may incorrectly interpret attacker-influenced responses as executable script.
CVSS Information
N/A
Vulnerability Type
对输出编码和转义不恰当
Vulnerability Title
Tenda W30E 安全漏洞
Vulnerability Description
Tenda W30E是中国腾达(Tenda)公司的一款路由器。 Tenda W30E V2 V16.01.0.19(5037)及之前版本存在安全漏洞,该漏洞源于Web管理界面缺少X-Content-Type-Options标头,可能导致浏览器错误解释响应为可执行脚本。
CVSS Information
N/A
Vulnerability Type
N/A