CVE-2024-46437 is a sensitive information disclosure vulnerability affecting the Tenda W18E V16.01.0.8(1625) web management portal. An unauthenticated remote attacker can exploit this by sending a crafted HTTP POST request to retrieve sensitive configuration data, including WiFi credentials and base64-encoded administrator credentials. This vulnerability has a CVSS score of 6.5 (Medium), indicating it can be exploited with low complexity over an adjacent network, leading to high confidentiality impact without requiring user interaction. Currently, there is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
16.01.0.8\(1625\)CPE matchmatch criteria | cpe:2.3:o:tenda:w18e_firmware:16.01.0.8\(1625\):*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.