← Vulnerability feed

Vulnerability record · CVE-2025-46632 · published 1 May 2025

CVE-2025-46632: Tenda rx2 pro firmware vulnerability

Tenda · Rx2 Pro Firmware

Initialization vector (IV) reuse in the web management portal of the Tenda RX2 Pro 16.03.30.14 may allow an attacker to discern information about or more easily decrypt encrypted messages between client and server.

6.5 CVSS 3.1 Medium EPSS 0.32% · top 78.0% CWE-323 · CWE-323
6.5CVSS 3.1 base score
0.32%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

Initialization vector (IV) reuse in the web management portal of the Tenda RX2 Pro 16.03.30.14 may allow an attacker to discern information about or more easily decrypt encrypted messages between client and server.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-46632 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2025-46625Tenda rx2 pro firmware command injection vulnerabilityLack of input validation/sanitization in the 'setLanCfg' API endpoint in httpd in the Tenda RX2 Pro 16.03.30.14 allows a remote attacker that is auth…EPSS 0.85%8.2CVE-2025-46633Tenda rx2 pro firmware cleartext storage of sensitive data vulnerabilityCleartext transmission of sensitive information in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an attacker to decrypt traffic b…EPSS 0.26%8.2CVE-2025-46634Tenda rx2 pro firmware cleartext storage of sensitive data vulnerabilityCleartext transmission of sensitive information in the web management portal of the Tenda RX2 Pro 16.03.30.14 may allow an unauthenticated attacker t…EPSS 0.17%8.2CVE-2025-46627Tenda rx2 pro firmware vulnerabilityUse of weak credentials in the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated attacker to authenticate to the telnet service by calculating the …EPSS 0.43%7.3CVE-2025-46626Tenda rx2 pro firmware inadequate encryption strength vulnerabilityReuse of a static AES key and initialization vector for encrypted traffic to the 'ate' management service of the Tenda RX2 Pro 16.03.30.14 allows an …EPSS 0.23%7.3CVE-2025-46628Tenda rx2 pro firmware improper access control vulnerabilityLack of input validation/sanitization in the 'ate' management service in the Tenda RX2 Pro 16.03.30.14 allows an unauthorized remote attacker to gain…EPSS 1.0%7.1CVE-2025-46635Tenda rx2 pro firmware improper access control vulnerabilityAn issue was discovered on Tenda RX2 Pro 16.03.30.14 devices. Improper network isolation between the guest Wi-Fi network and other network interfaces…EPSS 0.33%6.5CVE-2025-46631Tenda rx2 pro firmware improper authentication vulnerabilityImproper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to enable telnet acc…EPSS 7.5%

Source: NIST National Vulnerability Database (record CVE-2025-46632), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.