Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) contain a stored cross-site scripting vulnerability in the user creation functionality. Insufficient input validation allows attacker-controlled script content to be stored and later executed when administrative users access the affected management pages.
| Software | From | Fixed in |
|---|---|---|
| tenda / w30e_firmware | - | 16.01.0.19\(5037\).x |