PT-2025-18699 · Tenda · Tenda Rx2 Pro
Published
2025-05-01
·
Updated
2025-05-27
·
CVE-2025-46625
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Tenda RX2 Pro version 16.03.30.14
Description
The issue is related to a lack of input validation/sanitization in the
setLanCfg API endpoint in httpd, allowing a remote attacker authorized to the web management portal to gain root shell access to the device by sending a crafted web request. This is a persistent issue because the command injection is saved in the device's configuration.Recommendations
For Tenda RX2 Pro version 16.03.30.14, as a temporary workaround, consider disabling the
setLanCfg API endpoint until a patch is available. Restrict access to the web management portal to minimize the risk of exploitation. Avoid using the setLanCfg endpoint in the affected API until the issue is resolved.Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tenda Rx2 Pro