216.73.216.233

CVE-2025-15371

· Published 31/12/2025 01:15 · Modified 31/12/2025 20:42

Labels: CVE-2025-15371 2025-12-31CVE-2025-15371CWE-259[email protected]

Essential information

Published
31/12/2025 01:15
Modified
31/12/2025 20:42
Author
Creator
CVSS
8.5 HIGH (v3) 8.5 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A vulnerability has been found in Tenda i24, 4G03 Pro, 4G05, 4G08, G0-8G-PoE, Nova MW5G and TEG5328F up to 65.10.15.6. Affected is an unknown function of the component Shadow File. Such manipulation with the input Fireitup leads to hard-coded credentials. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
tenda / i24 cpe:2.3:a:tenda:i24:*:*:*:*:*:*:*:*
tenda / 4g03 pro cpe:2.3:a:tenda:4g03_pro:*:*:*:*:*:*:*:*
tenda / 4g05 cpe:2.3:a:tenda:4g05:*:*:*:*:*:*:*:*
tenda / 4g08 cpe:2.3:a:tenda:4g08:*:*:*:*:*:*:*:*
tenda / g0-8g-poe cpe:2.3:a:tenda:g0-8g-poe:*:*:*:*:*:*:*:*
tenda / nova mw5g cpe:2.3:a:tenda:nova_mw5g:*:*:*:*:*:*:*:*
tenda / teg5328f cpe:2.3:a:tenda:teg5328f:*:*:*:*:*:*:*:*

References