PT-2025-18701 · Tenda · Tenda Rx2 Pro
Published
2025-05-01
·
Updated
2025-05-03
·
CVE-2025-46627
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:N/C:C/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Tenda RX2 Pro version 16.03.30.14
Description
The issue concerns the use of weak credentials, allowing an unauthenticated attacker to authenticate to the telnet service. This is achieved by calculating the root password based on easily obtained device information, specifically the last two digits/octets of the MAC address.
Recommendations
For Tenda RX2 Pro version 16.03.30.14, consider changing the default root password to a strong and unique one to prevent unauthorized access to the telnet service. As a temporary workaround, restrict access to the telnet service until a more secure authentication mechanism is implemented.
Exploit
Fix
Insecure Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tenda Rx2 Pro