CVE-2025-11666
Severity CVSS v4.0:
HIGH
Type:
CWE-255
Credentials Management
Publication date:
13/10/2025
Last modified:
14/10/2025
Description
A flaw has been found in Tenda RP3 Pro up to 22.5.7.93. This impacts an unknown function of the file force_upgrade.sh of the component Firmware Update Handler. Executing manipulation of the argument current_force_upgrade_pwd can lead to use of hard-coded password. The attack can only be executed locally. The exploit has been published and may be used.
Impact
Base Score 4.0
8.40
Severity 4.0
HIGH
Base Score 3.x
6.70
Severity 3.x
MEDIUM
Base Score 2.0
6.50
Severity 2.0
MEDIUM



