Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-13236 | Lack of access controls in the 'ate' management binary of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to perform unauthorized configuration changes for any router where 'ate' has been enabled by sending a crafted UDP packet |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 27 May 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tenda
Tenda rx2 Pro Tenda rx2 Pro Firmware |
|
| CPEs | cpe:2.3:h:tenda:rx2_pro:-:*:*:*:*:*:*:* cpe:2.3:o:tenda:rx2_pro_firmware:16.03.30.14:*:*:*:*:*:*:* |
|
| Vendors & Products |
Tenda
Tenda rx2 Pro Tenda rx2 Pro Firmware |
Fri, 02 May 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 02 May 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 | |
| Metrics |
cvssV3_1
|
Thu, 01 May 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Lack of access controls in the 'ate' management binary of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to perform unauthorized configuration changes for any router where 'ate' has been enabled by sending a crafted UDP packet | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-05-02T15:11:42.416Z
Reserved: 2025-04-26T00:00:00.000Z
Link: CVE-2025-46629
Updated: 2025-05-02T15:11:19.397Z
Status : Analyzed
Published: 2025-05-01T20:15:38.660
Modified: 2025-05-27T14:24:23.877
Link: CVE-2025-46629
No data.
OpenCVE Enrichment
No data.
EUVD