CVE-2025-46634 Details
Description
Cleartext transmission of sensitive information in the web management portal of the Tenda RX2 Pro 16.03.30.14 may allow an unauthenticated attacker to authenticate to the web management portal by collecting credentials from observed/collected traffic. It implements encryption, but not until after the user has transmitted the hash of their password in cleartext. The hash can be replayed to authenticate.
A vulnerability exists in the Tenda RX2 Pro Wi-Fi 6 router, specifically in version 16.03.30.14, due to the cleartext transmission of sensitive information through the web management portal. This flaw may allow an unauthenticated attacker to intercept and collect credentials from unencrypted traffic, enabling access to the management portal. Although the router implements encryption, it only activates after the user has transmitted a hashed password in cleartext. The intercepted hash can be replayed to authenticate.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 2, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://blog.uturn.dev/#/writeups/iot-village/tenda-rx2pro/README?id=cve-2025-46634-transmission-of-plaintext-credentials-in-httpd | [email protected] | ExploitThird Party Advisory |
| https://www.tendacn.com/us/default.html | [email protected] | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-312 | Cleartext Storage of Sensitive Information | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| tenda rx2 pro firmware | 16.03.30.14 |
CPE
Remediation
| |
| tenda rx2 pro | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 27, 2025 | Initial Analysis | [email protected] |
| May 2, 2025 | CVE Modified | CISA-ADP |
| May 1, 2025 | New CVE Received | [email protected] |