Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.5

Tenda W15E: Unauthorized access to configuration file with admin credentials

CVE-2026-30140
Summary

An attacker can download a configuration file from a Tenda W15E router, which includes administrator login credentials. This could allow the attacker to gain unauthorized access to the router and potentially take control of it. To protect your network, update your router's firmware to the latest version.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
tenda w15e_firmware 02.03.01.26_cn –
Original title
An incorrect access control vulnerability exists in Tenda W15E V02.03.01.26_cn. An unauthenticated attacker can access the /cgi-bin/DownloadCfg/RouterCfm.jpg endpoint to download the configuration ...
Original description
An incorrect access control vulnerability exists in Tenda W15E V02.03.01.26_cn. An unauthenticated attacker can access the /cgi-bin/DownloadCfg/RouterCfm.jpg endpoint to download the configuration file containing plaintext administrator credentials, leading to sensitive information disclosure and potential remote administrative access.
Vulnerability type
CWE-284 Improper Access Control
Published: 9 Mar 2026 · Updated: 13 Mar 2026 · First seen: 9 Mar 2026