CVE-2026-38835 | Tenda W30E 2.0/16.01.0.21 formSetUSBPartitionUmount usbPartitionName command injection
A vulnerability was found in Tenda W30E 2.0/16.01.0.21. It has been declared as critical. This impacts the function formSetUSBPartitionUmount. Such manipulation of the argument usbPartitionName leads to command injection.
This vulnerability is uniquely identified as CVE-2026-38835. The attack can be launched remotely. No exploit exists.