We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-46625



Description

Lack of input validation/sanitization in the 'setLanCfg' API endpoint in httpd in the Tenda RX2 Pro 16.03.30.14 allows a remote attacker that is authorized to the web management portal to gain root shell access to the device by sending a crafted web request. This is persistent because the command injection is saved in the configuration of the device.

Reserved 2025-04-26 | Published 2025-05-01 | Updated 2025-05-02 | Assigner mitre

References

www.tendacn.com/us/default.html

blog.uturn.dev/

cve.org (CVE-2025-46625)

nvd.nist.gov (CVE-2025-46625)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-46625

Support options

Helpdesk Chat, Email, Knowledgebase