← Vulnerability feed

Vulnerability record · CVE-2025-46625 · published 1 May 2025

CVE-2025-46625: Tenda rx2 pro firmware command injection vulnerability

Tenda · Rx2 Pro Firmware

Lack of input validation/sanitization in the 'setLanCfg' API endpoint in httpd in the Tenda RX2 Pro 16.03.30.14 allows a remote attacker that is authorized to the web management portal to gain root shell access to the device by sending a crafted web request. This is persistent because the command injection is saved in the configuration of the device.

8.8 CVSS 3.1 High EPSS 0.85% · top 43.6% CWE-77 · Command injection
8.8CVSS 3.1 base score
0.85%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Lack of input validation/sanitization in the 'setLanCfg' API endpoint in httpd in the Tenda RX2 Pro 16.03.30.14 allows a remote attacker that is authorized to the web management portal to gain root shell access to the device by sending a crafted web request. This is persistent because the command injection is saved in the configuration of the device.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-46625 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.2CVE-2025-46633Tenda rx2 pro firmware cleartext storage of sensitive data vulnerabilityCleartext transmission of sensitive information in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an attacker to decrypt traffic b…EPSS 0.26%8.2CVE-2025-46634Tenda rx2 pro firmware cleartext storage of sensitive data vulnerabilityCleartext transmission of sensitive information in the web management portal of the Tenda RX2 Pro 16.03.30.14 may allow an unauthenticated attacker t…EPSS 0.17%8.2CVE-2025-46627Tenda rx2 pro firmware vulnerabilityUse of weak credentials in the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated attacker to authenticate to the telnet service by calculating the …EPSS 0.43%7.3CVE-2025-46626Tenda rx2 pro firmware inadequate encryption strength vulnerabilityReuse of a static AES key and initialization vector for encrypted traffic to the 'ate' management service of the Tenda RX2 Pro 16.03.30.14 allows an …EPSS 0.23%7.3CVE-2025-46628Tenda rx2 pro firmware improper access control vulnerabilityLack of input validation/sanitization in the 'ate' management service in the Tenda RX2 Pro 16.03.30.14 allows an unauthorized remote attacker to gain…EPSS 1.0%7.1CVE-2025-46635Tenda rx2 pro firmware improper access control vulnerabilityAn issue was discovered on Tenda RX2 Pro 16.03.30.14 devices. Improper network isolation between the guest Wi-Fi network and other network interfaces…EPSS 0.33%6.5CVE-2025-46631Tenda rx2 pro firmware improper authentication vulnerabilityImproper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to enable telnet acc…EPSS 7.5%6.5CVE-2025-46632Tenda rx2 pro firmware vulnerabilityInitialization vector (IV) reuse in the web management portal of the Tenda RX2 Pro 16.03.30.14 may allow an attacker to discern information about or …EPSS 0.32%

Source: NIST National Vulnerability Database (record CVE-2025-46625), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.