Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w69g-qrmr-3cf2

Опубликовано: 26 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 2.1
CVSS3: 6.5

Описание

Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) fail to include the X-Content-Type-Options: nosniff response header on web management interfaces. As a result, browsers that perform MIME sniffing may incorrectly interpret attacker-influenced responses as executable script.

Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) fail to include the X-Content-Type-Options: nosniff response header on web management interfaces. As a result, browsers that perform MIME sniffing may incorrectly interpret attacker-influenced responses as executable script.

EPSS

Процентиль: 10%
0.00036
Низкий

2.1 Low

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-116

Связанные уязвимости

CVSS3: 6.5
nvd
8 дней назад

Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) fail to include the X-Content-Type-Options: nosniff response header on web management interfaces. As a result, browsers that perform MIME sniffing may incorrectly interpret attacker-influenced responses as executable script.

CVSS3: 6.5
fstec
9 дней назад

Уязвимость веб-интерфейса управления микропрограммного обеспечения маршрутизаторов Tenda W30E, позволяющая нарушителю проводить межсайтовые сценарные атаки (XSS)

EPSS

Процентиль: 10%
0.00036
Низкий

2.1 Low

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-116