CVE-2024-46429: Tenda w18e Firmware

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

A hardcoded credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access the web management portal using a default guest account with administrative privileges.

Affected products

  • Tenda w18e Firmware: version 16.01.0.8(1625) only

Published 2025-02-10. Last modified 2026-06-17.