PT-2025-18701 · Tenda · Tenda Rx2 Pro

Published

2025-05-01

·

Updated

2025-05-03

·

CVE-2025-46627

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:N/C:C/I:P/A:N
Name of the Vulnerable Software and Affected Versions Tenda RX2 Pro version 16.03.30.14
Description The issue concerns the use of weak credentials, allowing an unauthenticated attacker to authenticate to the telnet service. This is achieved by calculating the root password based on easily obtained device information, specifically the last two digits/octets of the MAC address.
Recommendations For Tenda RX2 Pro version 16.03.30.14, consider changing the default root password to a strong and unique one to prevent unauthorized access to the telnet service. As a temporary workaround, restrict access to the telnet service until a more secure authentication mechanism is implemented.

Exploit

Fix

Insecure Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-05629
CVE-2025-46627

Affected Products

Tenda Rx2 Pro