Tenda W18E V16.01.0.8(1625) is vulnerable to Incorrect Access Control. An attacker can send a specially crafted HTTP POST request to the setQuickCfgWifiAndLogin function, which allows unauthorized changes to WiFi configuration settings and administrative credentials.
2025-02-10T19:15:38.540
2025-03-25T18:13:06.687
Analyzed
CVSSv3.1: 8.8 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | tenda | w18e_firmware | 16.01.0.8\(1625\) | Yes |
| Hardware | tenda | w18e | - | No |