CVE-2025-9309 Details
Description
A vulnerability was found in Tenda AC10 16.03.10.13. Affected is an unknown function of the file /etc_ro/shadow of the component MD5 Hash Handler. Performing manipulation results in hard-coded credentials. The attack needs to be approached locally. A high degree of complexity is needed for the attack. The exploitability is told to be difficult. The exploit has been made public and could be used.
A hard-coded credentials vulnerability exists in the Tenda AC10 Wi-Fi 5 router, specifically in the firmware version 16.03.10.13. The vulnerability arises from the root user's password, which is hard-coded, stored in the file /etc_ro/shadow, and hashed using MD5-crypt. This hash can be easily cracked with tools like John the Ripper, revealing the password 'Fireitup'. The cracked password allows unauthorized access to the device with root privileges, through network-accessible services or the administrative interface.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 21, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/XXRicardo/iot-cve/blob/main/Tenda/AC10/V4.0si_V16.03.10.13.md | CISA-ADP | ExploitThird Party Advisory |
| https://github.com/XXRicardo/iot-cve/blob/main/Tenda/AC10/V4.0si_V16.03.10.13.md#steps-to-reproduce | CISA-ADP | ExploitThird Party Advisory |
| https://github.com/XXRicardo/iot-cve/blob/main/Tenda/AC10/V4.0si_V16.03.10.13.md | [email protected] | ExploitThird Party Advisory |
| https://github.com/XXRicardo/iot-cve/blob/main/Tenda/AC10/V4.0si_V16.03.10.13.md#steps-to-reproduce | [email protected] | ExploitThird Party Advisory |
| https://vuldb.com/?ctiid.320914 | [email protected] | Permissions RequiredVDB Entry |
| https://vuldb.com/?id.320914 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/?submit.633585 | [email protected] | Third Party AdvisoryVDB Entry |
| https://www.tenda.com.cn/ | [email protected] | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-259 | Use of Hard-coded Password | [email protected] |
| CWE-798 | Use of Hard-coded Credentials | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| tenda ac10 firmware | 16.03.10.13 |
CPE
Remediation
| |
| tenda ac10 | 4.0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Aug 25, 2025 | Initial Analysis | [email protected] |
| Aug 21, 2025 | CVE Modified | CISA-ADP |
| Aug 21, 2025 | New CVE Received | [email protected] |