CVE-2025-9309

LOW

Tenda AC10 16.03.10.13 - Info Disclosure

Title source: llm
STIX 2.1

Description

A vulnerability was found in Tenda AC10 16.03.10.13. Affected is an unknown function of the file /etc_ro/shadow of the component MD5 Hash Handler. Performing manipulation results in hard-coded credentials. The attack needs to be approached locally. A high degree of complexity is needed for the attack. The exploitability is told to be difficult. The exploit has been made public and could be used.

Scores

CVSS v3 2.5
EPSS 0.0002
EPSS Percentile 5.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-259 CWE-798
Status published
Products (1)
tenda/ac10_firmware 16.03.10.13
Published Aug 21, 2025
Tracked Since Feb 18, 2026