Metrics
Affected Vendors & Products
| Source | ID | Title | 
|---|---|---|
  EUVD | 
                EUVD-2025-25104 | A security flaw has been discovered in Tenda AC20 16.03.08.12. Affected by this vulnerability is an unknown functionality of the file /etc_ro/shadow. The manipulation leads to hard-coded credentials. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. | 
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 21 Aug 2025 16:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Tenda ac20 Firmware
         | 
|
| CPEs | cpe:2.3:h:tenda:ac20:-:*:*:*:*:*:*:* cpe:2.3:o:tenda:ac20_firmware:16.03.08.12:*:*:*:*:*:*:*  | 
|
| Vendors & Products | 
        
        Tenda ac20 Firmware
         | 
Mon, 18 Aug 2025 21:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Tenda
         Tenda ac20  | 
|
| Vendors & Products | 
        
        Tenda
         Tenda ac20  | 
Mon, 18 Aug 2025 14:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
         | |
| Metrics | 
        
        ssvc
         
  | 
Sun, 17 Aug 2025 02:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | A security flaw has been discovered in Tenda AC20 16.03.08.12. Affected by this vulnerability is an unknown functionality of the file /etc_ro/shadow. The manipulation leads to hard-coded credentials. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. | |
| Title | Tenda AC20 shadow hard-coded credentials | |
| Weaknesses | CWE-259 CWE-798  | 
|
| References | 
         | |
| Metrics | 
        
        cvssV2_0
         
 
 
 
  | 
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-08-18T13:15:19.094Z
Reserved: 2025-08-16T06:06:25.733Z
Link: CVE-2025-9091
Updated: 2025-08-18T13:15:09.960Z
Status : Analyzed
Published: 2025-08-17T03:15:27.650
Modified: 2025-08-21T16:10:43.800
Link: CVE-2025-9091
No data.
                        OpenCVE Enrichment
                    Updated: 2025-08-18T20:46:37Z
 EUVD