PT-2025-18703 · Tenda · Tenda Rx2 Pro

Published

2025-05-01

·

Updated

2025-05-03

·

CVE-2025-46629

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Tenda RX2 Pro version 16.03.30.14
Description The issue is related to a lack of access controls in the 'ate' management binary, allowing an unauthenticated remote attacker to make unauthorized configuration changes to any router where 'ate' is enabled. This can be achieved by sending a crafted UDP packet.
Recommendations For Tenda RX2 Pro version 16.03.30.14, consider disabling the 'ate' management binary until a patch is available to prevent unauthorized configuration changes. Restrict access to the router to minimize the risk of exploitation.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2025-46629

Affected Products

Tenda Rx2 Pro