CVE Vulnerabilities

CVE-2025-46626

Inadequate Encryption Strength

Published: May 01, 2025 | Modified: May 02, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Reuse of a static AES key and initialization vector for encrypted traffic to the ate management service of the Tenda RX2 Pro 16.03.30.14 allows an attacker to decrypt, replay, and/or forge traffic to the service.

Weakness

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

Potential Mitigations

References