Home

Description

Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the do_ping_action function via the hostName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

PUBLISHED Reserved 2026-04-06 | Published 2026-04-21 | Updated 2026-04-21 | Assigner mitre

References

github.com/jsjbcyber/repo/blob/main/rep_1.md exploit

github.com/jsjbcyber/repo/blob/main/rep_1.md

cve.org (CVE-2026-38834)

nvd.nist.gov (CVE-2026-38834)

Download JSON