PT-2025-41760 · Tenda · Tenda Rp3 Pro

Iot_Res

·

Published

2025-10-11

·

Updated

2025-10-13

·

CVE-2025-11666

CVSS v2.0

6.8

Medium

VectorAV:L/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Tenda RP3 Pro versions through 22.5.7.93
Description A security issue exists in Tenda RP3 Pro up to version 22.5.7.93, specifically within the Firmware Update Handler component. Manipulation of the current force upgrade pwd argument in the force upgrade.sh file can result in the use of a hard-coded password. This issue can only be exploited locally. The exploit for this issue has been published.
Recommendations Update to a version later than 22.5.7.93.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BDU:2025-13329
CVE-2025-11666

Affected Products

Tenda Rp3 Pro