CVE-2025-46626 Details
Description
Reuse of a static AES key and initialization vector for encrypted traffic to the 'ate' management service of the Tenda RX2 Pro 16.03.30.14 allows an attacker to decrypt, replay, and/or forge traffic to the service.
A vulnerability exists in the Tenda RX2 Pro router, specifically in version 16.03.30.14, due to the reuse of a static AES key and initialization vector (IV) for encrypted traffic to the 'ate' management service. This flaw allows an attacker to decrypt, replay, and forge traffic to the service. The issue arises because the 'ate' service uses a static key and IV, with the key being 'Tenda0123456789M' and the IV consisting of 16 null bytes.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 2, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://blog.uturn.dev/#/writeups/iot-village/tenda-rx2pro/README?id=cve-2025-46625-command-injection-through-setlancfg-in-httpd | [email protected] | ExploitThird Party Advisory |
| https://www.tendacn.com/us/default.html | [email protected] | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-326 | Inadequate Encryption Strength | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| tenda rx2 pro firmware | 16.03.30.14 |
CPE
Remediation
| |
| tenda rx2 pro | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 27, 2025 | Initial Analysis | [email protected] |
| May 2, 2025 | CVE Modified | CISA-ADP |
| May 1, 2025 | New CVE Received | [email protected] |