CVE-2025-46630

Improper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to enable 'ate' (a remote system management binary) by sending a /goform/ate web request.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tenda:rx2_pro_firmware:16.03.30.14:*:*:*:*:*:*:*
cpe:2.3:h:tenda:rx2_pro:-:*:*:*:*:*:*:*

History

27 May 2025, 14:24

Type Values Removed Values Added
References () https://blog.uturn.dev/#/writeups/iot-village/tenda-rx2pro/README?id=cve-2025-46630-enable-ate-unauthenticated-through-httpd - () https://blog.uturn.dev/#/writeups/iot-village/tenda-rx2pro/README?id=cve-2025-46630-enable-ate-unauthenticated-through-httpd - Third Party Advisory, Exploit
References () https://www.tendacn.com/us/default.html - () https://www.tendacn.com/us/default.html - Product
First Time Tenda rx2 Pro
Tenda
Tenda rx2 Pro Firmware
CPE cpe:2.3:h:tenda:rx2_pro:-:*:*:*:*:*:*:*
cpe:2.3:o:tenda:rx2_pro_firmware:16.03.30.14:*:*:*:*:*:*:*

02 May 2025, 15:15

Type Values Removed Values Added
CWE CWE-287
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

02 May 2025, 13:52

Type Values Removed Values Added
Summary
  • (es) Los controles de acceso inadecuados en el portal de administración web de Tenda RX2 Pro 16.03.30.14 permiten que un atacante remoto no autenticado habilite 'ate' (un binario de administración del sistema remoto) enviando una solicitud web /goform/ate.

01 May 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-01 20:15

Updated : 2025-05-27 14:24


NVD link : CVE-2025-46630

Mitre link : CVE-2025-46630

CVE.ORG link : CVE-2025-46630


JSON object : View

Products Affected

tenda

  • rx2_pro_firmware
  • rx2_pro
CWE
CWE-287

Improper Authentication