Lack of access controls in the 'ate' management binary of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to perform unauthorized configuration changes for any router where 'ate' has been enabled by sending a crafted UDP packet
References
Link | Resource |
---|---|
https://blog.uturn.dev/#/writeups/iot-village/tenda-rx2pro/README?id=cve-2025-46629-lack-of-authentication-in-ate | Third Party Advisory Exploit |
https://www.tendacn.com/us/default.html | Product |
Configurations
Configuration 1 (hide)
AND |
|
History
27 May 2025, 14:24
Type | Values Removed | Values Added |
---|---|---|
References | () https://blog.uturn.dev/#/writeups/iot-village/tenda-rx2pro/README?id=cve-2025-46629-lack-of-authentication-in-ate - Third Party Advisory, Exploit | |
References | () https://www.tendacn.com/us/default.html - Product | |
CPE | cpe:2.3:o:tenda:rx2_pro_firmware:16.03.30.14:*:*:*:*:*:*:* cpe:2.3:h:tenda:rx2_pro:-:*:*:*:*:*:*:* |
|
First Time |
Tenda
Tenda rx2 Pro Firmware Tenda rx2 Pro |
02 May 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-284 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
02 May 2025, 13:52
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
01 May 2025, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-01 20:15
Updated : 2025-05-27 14:24
NVD link : CVE-2025-46629
Mitre link : CVE-2025-46629
CVE.ORG link : CVE-2025-46629
JSON object : View
Products Affected
tenda
- rx2_pro_firmware
- rx2_pro
CWE
CWE-284
Improper Access Control