CVE-2025-46629

MEDIUM

Tenda RX2 Pro 16.03.30.14 - Unauth RCE

Title source: llm
STIX 2.1

Description

Lack of access controls in the 'ate' management binary of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to perform unauthorized configuration changes for any router where 'ate' has been enabled by sending a crafted UDP packet

Scores

CVSS v3 6.5
EPSS 0.0019
EPSS Percentile 41.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (1)
tenda/rx2_pro_firmware 16.03.30.14
Published May 01, 2025
Tracked Since Feb 18, 2026