CVE-2025-46632 Details
Description
Initialization vector (IV) reuse in the web management portal of the Tenda RX2 Pro 16.03.30.14 may allow an attacker to discern information about or more easily decrypt encrypted messages between client and server.
A vulnerability exists in the web management portal of the Tenda RX2 Pro router, specifically in version 16.03.30.14, due to the reuse of the initialization vector (IV) in AES-128-CBC encryption. This IV reuse may allow an attacker to discern information or more easily decrypt messages encrypted between the client and server.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 2, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://blog.uturn.dev/#/writeups/iot-village/tenda-rx2pro/README?id=cve-2025-46632-static-iv-use-in-httpd | [email protected] | ExploitThird Party Advisory |
| https://www.tendacn.com/us/default.html | [email protected] | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-323 | Reusing a Nonce, Key Pair in Encryption | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| tenda rx2 pro firmware | 16.03.30.14 |
CPE
Remediation
| |
| tenda rx2 pro | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 27, 2025 | Initial Analysis | [email protected] |
| May 2, 2025 | CVE Modified | CISA-ADP |
| May 1, 2025 | New CVE Received | [email protected] |