6.5
CVE-2025-46629
- EPSS 0.2%
- Veröffentlicht 01.05.2025 00:00:00
- Zuletzt bearbeitet 27.05.2025 14:24:23
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Lack of access controls in the 'ate' management binary of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to perform unauthorized configuration changes for any router where 'ate' has been enabled by sending a crafted UDP packet
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tenda ≫ Rx2 Pro Firmware Version16.03.30.14
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.2% | 0.414 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 6.5 | 3.9 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.