Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 16 Apr 2026 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated Router Configuration File Disclosure due to Incorrect Access Control |
Fri, 13 Mar 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tenda w15e Firmware
|
|
| CPEs | cpe:2.3:h:tenda:w15e:-:*:*:*:*:*:*:* cpe:2.3:o:tenda:w15e_firmware:02.03.01.26_cn:*:*:*:*:*:*:* |
|
| Vendors & Products |
Tenda w15e Firmware
|
Wed, 11 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 | |
| Metrics |
cvssV3_1
|
Tue, 10 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tenda
Tenda w15e |
|
| Vendors & Products |
Tenda
Tenda w15e |
Mon, 09 Mar 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An incorrect access control vulnerability exists in Tenda W15E V02.03.01.26_cn. An unauthenticated attacker can access the /cgi-bin/DownloadCfg/RouterCfm.jpg endpoint to download the configuration file containing plaintext administrator credentials, leading to sensitive information disclosure and potential remote administrative access. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-03-11T14:28:39.384Z
Reserved: 2026-03-04T00:00:00.000Z
Link: CVE-2026-30140
Updated: 2026-03-11T14:28:33.337Z
Status : Analyzed
Published: 2026-03-09T19:16:07.303
Modified: 2026-03-13T19:40:00.567
Link: CVE-2026-30140
No data.
OpenCVE Enrichment
Updated: 2026-04-16T04:15:24Z