Impact
The vulnerability arises in the hostapd component of Tenda CP3 firmware 27.5.57.101. By manipulating the wpa_passphrase parameter, an attacker can trigger the use of hard‑coded credentials, allowing unauthorized authentication to the device. This can compromise the confidentiality, integrity, or availability of the network managed by the AP if the attacker gains administrative control.
Affected Systems
The flaw affects Tenda CP3 routers running firmware version 27.5.57.101. Other versions not listed are assumed not to be impacted unless they include the same hostapd implementation. Users of the CP3 product line should verify their firmware version against the vulnerability listing.
Risk and Exploitability
The CVSS score of 5.1 points to a moderate risk. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog, suggesting it is not yet widely exploited. However, the attack vector is remote, likely over the wireless interface, which permits any nearby device to submit a crafted wpa_passphrase. Because the credentials are hard‑coded, an attacker does not need to discover passwords; they can simply authenticate with the known default values once the flaw is triggered.
OpenCVE Enrichment