Tenda W30E v1.0.1.25(633) was discovered to contain a command injection vulnerability via the fileNameMit parameter at /goform/delFileName.
- https://github.com/z1r00/IOT_Vul/blob/main/Tenda/W30E/delFileName/readme.md
- https://github.com/ARPSyndicate/cvemon
- https://github.com/z1r00/IOT_Vul