CVE Vulnerabilities

CVE-2025-46626

Inadequate Encryption Strength

Published: May 01, 2025 | Modified: May 27, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Reuse of a static AES key and initialization vector for encrypted traffic to the ate management service of the Tenda RX2 Pro 16.03.30.14 allows an attacker to decrypt, replay, and/or forge traffic to the service.

Weakness

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

Affected Software

Name Vendor Start Version End Version
Rx2_pro_firmware Tenda 16.03.30.14 (including) 16.03.30.14 (including)

Potential Mitigations

References