CVE-2025-52054

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
28/08/2025
Last modified:
09/09/2025

Description

An issue was discovered in Tenda AC8 v4.0 AC1200 Dual-band Gigabit Wireless Router AC8v4.0 Firmware 16.03.33.05. The root password of the device is calculated with a static string and the last two octets of the MAC address of the device. This allows an unauthenticated attacker to authenticate with network services on the device.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:tenda:ac8_firmware:*:*:*:*:*:*:*:* 16.03.33.05 (including)
cpe:2.3:h:tenda:ac8:4.0:*:*:*:*:*:*:*