CVE Vulnerabilities

CVE-2025-46627

Insecure Storage of Sensitive Information

Published: May 01, 2025 | Modified: May 27, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Use of weak credentials in the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated attacker to authenticate to the telnet service by calculating the root password based on easily-obtained device information. The password is based on the last two digits/octets of the MAC address.

Weakness

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

Affected Software

NameVendorStart VersionEnd Version
Rx2_pro_firmwareTenda16.03.30.14 (including)16.03.30.14 (including)

References