CVE-2024-24488
https://notcve.org/view.php?id=CVE-2024-24488
An issue in Shenzen Tenda Technology CP3V2.0 V11.10.00.2311090948 allows a local attacker to obtain sensitive information via the password component. Un problema en Shenzen Tenda Technology CP3V2.0 V11.10.00.2311090948 permite a un atacante local obtener información confidencial a través del componente de contraseña. • https://github.com/minj-ae/CVE-2024-24488 • CWE-312: Cleartext Storage of Sensitive Information •
CVE-2023-23080
https://notcve.org/view.php?id=CVE-2023-23080
Certain Tenda products are vulnerable to command injection. This affects Tenda CP7 Tenda CP7<=V11.10.00.2211041403 and Tenda CP3 v.10 Tenda CP3 v.10<=V20220906024_2025 and Tenda IT7-PCS Tenda IT7-PCS<=V2209020914 and Tenda IT7-LCS Tenda IT7-LCS<=V2209020914 and Tenda IT7-PRS Tenda IT7-PRS<=V2209020908. • https://github.com/fxc233/iot-vul/tree/main/Tenda/IPC • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •