Description
A weakness has been identified in Tenda 4G03 Pro 1.0/1.0re/01.bin/04.03.01.53. Affected by this issue is some unknown functionality of the file /etc/www/pem/server.key of the component ECDSA P-256 Private Key Handler. This manipulation causes use of hard-coded cryptographic key . It is possible to initiate the attack remotely.
Problem types
Use of Hard-coded Cryptographic Key
Product status
1.0re
01.bin
04.03.01.53
Timeline
| 2026-04-04: | Advisory disclosed |
| 2026-04-04: | VulDB entry created |
| 2026-04-04: | VulDB entry last update |
Credits
CoreNode (VulDB User)
VulDB Vulnerability Moderation Team
References
vuldb.com/vuln/355280 (VDB-355280 | Tenda 4G03 Pro ECDSA P-256 Private Key server.key hard-coded key)
vuldb.com/vuln/355280/cti (VDB-355280 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/submit/782053 (Submit #782053 | Tenda 4G03 Pro V1.0 V04.03.01.53 Cryptographic Issues)
www.tenda.com.cn/