A flaw has been found in Tenda RP3 Pro up to 22.5.7.93. This impacts an unknown function of the file force_upgrade.sh of the component Firmware Update Handler. Executing manipulation of the argument current_force_upgrade_pwd can lead to use of hard-coded password. The attack can only be executed locally. The exploit has been published and may be used.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 13 Oct 2025 07:15:00 +0000

Type Values Removed Values Added
Description A flaw has been found in Tenda RP3 Pro up to 22.5.7.93. This impacts an unknown function of the file force_upgrade.sh of the component Firmware Update Handler. Executing manipulation of the argument current_force_upgrade_pwd can lead to use of hard-coded password. The attack can only be executed locally. The exploit has been published and may be used.
Title Tenda RP3 Pro Firmware Update force_upgrade.sh hard-coded password
Weaknesses CWE-255
CWE-259
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:L/AC:L/Au:M/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.7, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2025-10-13T07:02:07.269Z

Reserved: 2025-10-12T13:14:23.093Z

Link: CVE-2025-11666

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-10-13T07:15:53.063

Modified: 2025-10-13T07:15:53.063

Link: CVE-2025-11666

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.