CVE-2025-46633 Details
Description
Cleartext transmission of sensitive information in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an attacker to decrypt traffic between the client and server by collecting the symmetric AES key from collected and/or observed traffic. The AES key in sent in cleartext in response to successful authentication. The IV is always EU5H62G9ICGRNI43.
A vulnerability exists in the Tenda RX2 Pro router's web management portal, specifically in version 16.03.30.14. The issue arises from the cleartext transmission of sensitive information, allowing an attacker to intercept and decrypt traffic between the client and server. This is possible because the symmetric AES key used for encryption is sent in cleartext after successful authentication. The initialization vector (IV) used in the encryption process is always the same, further compromising the security of the transmission.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 2, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://blog.uturn.dev/#/writeups/iot-village/tenda-rx2pro/README?id=cve-2025-46633-transmission-of-plaintext-symmetric-key-in-httpd | [email protected] | ExploitThird Party Advisory |
| https://www.tendacn.com/us/default.html | [email protected] | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-312 | Cleartext Storage of Sensitive Information | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| tenda rx2 pro firmware | 16.03.30.14 |
CPE
Remediation
| |
| tenda rx2 pro | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 27, 2025 | Initial Analysis | [email protected] |
| May 2, 2025 | CVE Modified | CISA-ADP |
| May 1, 2025 | New CVE Received | [email protected] |