6.8

CVE-2025-52363

Exploit
Tenda CP3 Pro Firmware V22.5.4.93 contains a hardcoded root password hash in the /etc/passwd file and /etc/passwd-. An attacker with access to the firmware image can extract and attempt to crack the root password hash, potentially obtaining administrative access
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tenda ≫ Cp3 Pro Firmware Version 22.5.4.93
   Tenda ≫ Cp3 Pro Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.106
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 6.8 2.5 4.2
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
CWE-798 Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

https://www.tendacn.com/product/download/cp3pro.html
Broken Link
https://cybermaya.in/posts/Post-39/
Third Party Advisory
Exploit