216.73.217.24

CVE-2025-46628

· Published 01/05/2025 20:15 · Modified 01/05/2025 20:15

Labels: CVE-2025-46628 2025-05-01CVE-2025-46628[email protected]

Essential information

Published
01/05/2025 20:15
Modified
01/05/2025 20:15
Author
Creator
CISA KEV
No
CWE

Description

Lack of input validation/sanitization in the 'ate' management service in the Tenda RX2 Pro 16.03.30.14 allows an unauthorized remote attacker to gain root shell access to the device by sending a crafted UDP packet to the 'ate' service when it is enabled. Authentication is not needed.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
tenda / rx2 pro cpe:2.3:a:tenda:rx2_pro:16.03.30.14:*:*:*:*:*:*:*

References