Lack of access controls in the 'ate' management binary of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to perform unauthorized configuration changes for any router where 'ate' has been enabled by sending a crafted UDP packet
References
| Link | Resource |
|---|---|
| https://blog.uturn.dev/#/writeups/iot-village/tenda-rx2pro/README?id=cve-2025-46629-lack-of-authentication-in-ate | Exploit Third Party Advisory |
| https://www.tendacn.com/us/default.html | Product |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2025-05-01 20:15
Updated : 2025-05-27 14:24
NVD link : CVE-2025-46629
Mitre link : CVE-2025-46629
CVE.ORG link : CVE-2025-46629
JSON object : View
Products Affected
tenda
- rx2_pro_firmware
- rx2_pro
CWE
CWE-284
Improper Access Control
