CVE-2025-15371

A vulnerability has been found in Tenda i24, 4G03 Pro, 4G05, 4G08, G0-8G-PoE, Nova MW5G and TEG5328F up to 65.10.15.6. Affected is an unknown function of the component Shadow File. Such manipulation with the input Fireitup leads to hard-coded credentials. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.
Configurations

No configuration.

History

31 Dec 2025, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-31 01:15

Updated : 2025-12-31 20:42


NVD link : CVE-2025-15371

Mitre link : CVE-2025-15371

CVE.ORG link : CVE-2025-15371


JSON object : View

Products Affected

No product.

CWE
CWE-259

Use of Hard-coded Password

CWE-798

Use of Hard-coded Credentials