PT-2025-35091 · Tenda · Tenda Ac1200+1

Published

2025-08-27

·

Updated

2025-08-28

·

CVE-2025-52054

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Tenda AC8 v4.0 AC1200 Dual-band Gigabit Wireless Router versions 16.03.33.05
Description An issue exists where the root password of the device is calculated using a static string and the last two octets of the device's MAC address. This allows an unauthenticated attacker to authenticate with network services on the device.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authentication

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

BDU:2025-12459
CVE-2025-52054

Affected Products

Tenda Ac1200
Tenda Ac8