CVE-2025-46625

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
01/05/2025
Last modified:
27/05/2025

Description

Lack of input validation/sanitization in the 'setLanCfg' API endpoint in httpd in the Tenda RX2 Pro 16.03.30.14 allows a remote attacker that is authorized to the web management portal to gain root shell access to the device by sending a crafted web request. This is persistent because the command injection is saved in the configuration of the device.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:tenda:rx2_pro_firmware:16.03.30.14:*:*:*:*:*:*:*
cpe:2.3:h:tenda:rx2_pro:-:*:*:*:*:*:*:*