CVE-2025-9731

LOW

Tenda AC9 15.03.05.19 - Hard-Coded Credentials

Title source: llm
STIX 2.1

Description

A vulnerability was determined in Tenda AC9 15.03.05.19. The impacted element is an unknown function of the file /etc_ro/shadow of the component Administrative Interface. This manipulation causes hard-coded credentials. It is possible to launch the attack on the local host. The attack's complexity is rated as high. The exploitability is regarded as difficult. The exploit has been publicly disclosed and may be utilized.

Scores

CVSS v3 2.5
EPSS 0.0002
EPSS Percentile 3.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-259 CWE-798
Status published
Products (1)
tenda/ac9_firmware 15.03.05.19
Published Aug 31, 2025
Tracked Since Feb 18, 2026