Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the formSetUSBPartitionUmount function via the usbPartitionName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Metrics
Affected Vendors & Products
References
History
Tue, 28 Apr 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Command Injection via USB Partition Name in Tenda W30E Router |
Tue, 28 Apr 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Command Injection Vulnerability in Tenda W30E via formSetUSBPartitionUmount | |
| Weaknesses | CWE-78 |
Mon, 27 Apr 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tenda w30e Firmware
|
|
| CPEs | cpe:2.3:h:tenda:w30e:2.0:*:*:*:*:*:*:* cpe:2.3:o:tenda:w30e_firmware:16.01.0.21:*:*:*:*:*:*:* |
|
| Vendors & Products |
Tenda w30e Firmware
|
Wed, 22 Apr 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 22 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Command Injection Vulnerability in Tenda W30E via formSetUSBPartitionUmount | |
| First Time appeared |
Tenda
Tenda w30e |
|
| Weaknesses | CWE-77 CWE-78 |
|
| Vendors & Products |
Tenda
Tenda w30e |
Tue, 21 Apr 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the formSetUSBPartitionUmount function via the usbPartitionName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-22T15:35:41.189Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-38835
Updated: 2026-04-22T13:53:02.279Z
Status : Analyzed
Published: 2026-04-21T17:16:53.357
Modified: 2026-04-27T16:44:10.893
Link: CVE-2026-38835
No data.