Insecure Permissions vulnerability in Tenda CP3 Pro Firmware V22.5.4.93 allows the telnet service (telnetd) by default at boot via the initialization script /etc/init.d/eth.sh. This allows remote attackers to connect to the device s shell over the network, potentially without authentication if default or weak credentials are present
                
            References
                    | Link | Resource | 
|---|---|
| https://cybermaya.in/posts/Post-40/ | Exploit Third Party Advisory | 
| https://www.tendacn.com/product/download/cp3pro.html | Broken Link | 
Configurations
                    Configuration 1 (hide)
| AND | 
            
            
 
  | 
    
History
                    07 Aug 2025, 18:02
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://cybermaya.in/posts/Post-40/ - Exploit, Third Party Advisory | |
| References | () https://www.tendacn.com/product/download/cp3pro.html - Broken Link | |
| First Time | 
        
        Tenda cp3 Pro Firmware
         Tenda Tenda cp3 Pro  | 
|
| CPE | cpe:2.3:o:tenda:cp3_pro_firmware:22.5.4.93:*:*:*:*:*:*:* cpe:2.3:h:tenda:cp3_pro:-:*:*:*:*:*:*:*  | 
14 Jul 2025, 17:15
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
        
        
  | 
10 Jul 2025, 13:17
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | 
        
        
  | 
09 Jul 2025, 21:15
| Type | Values Removed | Values Added | 
|---|---|---|
| CWE | CWE-1391 | |
| CVSS | 
        v2 :  v3 :  | 
    
        v2 : unknown
         v3 : 7.5  | 
09 Jul 2025, 15:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-07-09 15:15
Updated : 2025-08-07 18:02
NVD link : CVE-2025-52364
Mitre link : CVE-2025-52364
CVE.ORG link : CVE-2025-52364
JSON object : View
Products Affected
                tenda
- cp3_pro_firmware
 - cp3_pro
 
CWE
                
                    
                        
                        CWE-1391
                        
            Use of Weak Credentials
