CVE-2025-46627
Last modified
CVE-2025-46627 is a high-severity vulnerability rated 8.2/10 on the CVSS scale. Use of weak credentials in the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated attacker to authenticate to the telnet service by calculating the root password based on easily-obtained device information. The password is based on the last two digits/octets of the MAC address.. EPSS estimates a 0.36% chance of exploitation in the next 30 days.
Description
Use of weak credentials in the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated attacker to authenticate to the telnet service by calculating the root password based on easily-obtained device information. The password is based on the last two digits/octets of the MAC address.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tenda | Rx2 Pro Firmware | 16.03.30.14 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-46627?
How severe is CVE-2025-46627?
How do I fix CVE-2025-46627?
Are you affected by CVE-2025-46627?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
