Tenda CP3 Pro Firmware V22.5.4.93 contains a hardcoded root password hash in the /etc/passwd file and /etc/passwd-. An attacker with access to the firmware image can extract and attempt to crack the root password hash, potentially obtaining administrative access
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sat, 02 Aug 2025 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Tenda
Tenda cp3 Pro
Tenda cp3 Pro Firmware
CPEs cpe:2.3:h:tenda:cp3_pro:-:*:*:*:*:*:*:*
cpe:2.3:o:tenda:cp3_pro_firmware:22.5.4.93:*:*:*:*:*:*:*
Vendors & Products Tenda
Tenda cp3 Pro
Tenda cp3 Pro Firmware

Tue, 15 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00012}


Mon, 14 Jul 2025 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-798
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Jul 2025 17:30:00 +0000

Type Values Removed Values Added
Description Tenda CP3 Pro Firmware V22.5.4.93 contains a hardcoded root password hash in the /etc/passwd file and /etc/passwd-. An attacker with access to the firmware image can extract and attempt to crack the root password hash, potentially obtaining administrative access
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-07-14T17:34:22.355Z

Reserved: 2025-06-16T00:00:00.000Z

Link: CVE-2025-52363

cve-icon Vulnrichment

Updated: 2025-07-14T17:33:15.768Z

cve-icon NVD

Status : Analyzed

Published: 2025-07-14T18:15:23.400

Modified: 2025-08-02T01:36:30.260

Link: CVE-2025-52363

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.