← Back to browse · API

CVE-2026-38835

Severity
CRITICAL
CVSS
9.8
EPSS
0.0215
Risk score
39.95
CISA KEV
No
PoC
No
Published
2026-04-21
Modified
2026-04-22
First seen
2026-08-07
Aliases
EUVD-2026-24163, GHSA-656R-GGPG-WMQM
Products
n/a:n/a n/a
Sources
euvd EUVD-2026-24163

Description

Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the formSetUSBPartitionUmount function via the usbPartitionName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

References