PT-2025-46661 · Tenda · Tenda Ac15
Published
2025-11-12
·
Updated
2025-11-13
·
CVE-2025-63666
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Tenda AC15 version 15.03.05.18 multi
Description
The authentication cookie used by the device exposes the account password hash to the client and utilizes a short, low-entropy suffix as the session identifier. An attacker with network access or the ability to execute JavaScript in a victim’s browser can steal the cookie and replay it to gain access to protected resources.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tenda Ac15