CVE-2023-46370: Tenda w18e Firmware

Critical severity, CVSS 9.8. EPSS: 18.1% chance of exploitation in the next 30 days.

Tenda W18E V16.01.0.8(1576) has a command injection vulnerability via the hostName parameter in the formSetNetCheckTools function.

Affected products

  • Tenda w18e Firmware: version 16.01.0.8(1576) only

Published 2023-10-25. Last modified 2026-06-17.