CVE-2026-38571 Details
Description
Cleartext storage and exposure of WPA2 credentials, and missing authentication on the rr/wr memory read/write commands, in the unauthenticated UART debug console of the Tenda N300 F3 (V603) allow a physically proximate attacker to obtain stored WPA2 credentials in cleartext and to read or write arbitrary memory via the serial console.
A vulnerability in the Tenda Wireless N300 Easy Setup Router, Model F3, running firmware V603, allows a physically proximate attacker to access stored WPA2 credentials in cleartext and to read or write arbitrary memory through the unauthenticated UART debug console. The WPA2 credentials are exposed via the boot log and NVRAM, while the memory access is facilitated by the console's register commands. This vulnerability arises from cleartext storage of sensitive information and missing authentication for critical functions, with potential impacts including unauthorized access to in-memory secrets, modification of the device's running state, and exploitation of the device's control flow, possibly leading to arbitrary code execution.
No vendor fix is available. It is recommended to avoid deploying the device where untrusted parties can access the UART header, as physical access is equivalent to full credential compromise.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 26, 2026CISA-ADP
Assessed Jun 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/ZEssaidi-CS/Vulnerability-research/tree/main/CVE-2026-38571 | CISA-ADP | ExploitTechnical Analysis |
| https://github.com/ZEssaidi-CS/Vulnerability-research/tree/main/CVE-2026-38571 | [email protected] | ExploitTechnical Analysis |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-312 | Cleartext Storage of Sensitive Information | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Tenda N300 F3 | V603 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 29, 2026 | CVE Modified | CISA-ADP |
| Jun 26, 2026 | New CVE Received | [email protected] |
Volerion