CVE-2025-46632

Initialization vector (IV) reuse in the web management portal of the Tenda RX2 Pro 16.03.30.14 may allow an attacker to discern information about or more easily decrypt encrypted messages between client and server.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tenda:rx2_pro_firmware:16.03.30.14:*:*:*:*:*:*:*
cpe:2.3:h:tenda:rx2_pro:-:*:*:*:*:*:*:*

History

27 May 2025, 14:17

Type Values Removed Values Added
First Time Tenda rx2 Pro
Tenda
Tenda rx2 Pro Firmware
CPE cpe:2.3:h:tenda:rx2_pro:-:*:*:*:*:*:*:*
cpe:2.3:o:tenda:rx2_pro_firmware:16.03.30.14:*:*:*:*:*:*:*
References () https://blog.uturn.dev/#/writeups/iot-village/tenda-rx2pro/README?id=cve-2025-46632-static-iv-use-in-httpd - () https://blog.uturn.dev/#/writeups/iot-village/tenda-rx2pro/README?id=cve-2025-46632-static-iv-use-in-httpd - Third Party Advisory, Exploit
References () https://www.tendacn.com/us/default.html - () https://www.tendacn.com/us/default.html - Product

02 May 2025, 15:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-323

02 May 2025, 13:52

Type Values Removed Values Added
Summary
  • (es) La reutilización del vector de inicialización (IV) en el portal de administración web de Tenda RX2 Pro 16.03.30.14 puede permitir que un atacante discierna información o descifre más fácilmente los mensajes cifrados entre el cliente y el servidor.

01 May 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-01 20:15

Updated : 2025-05-27 14:17


NVD link : CVE-2025-46632

Mitre link : CVE-2025-46632

CVE.ORG link : CVE-2025-46632


JSON object : View

Products Affected

tenda

  • rx2_pro_firmware
  • rx2_pro
CWE
CWE-323

Reusing a Nonce, Key Pair in Encryption