CVE-2026-5527 Details
Description
A weakness has been identified in Tenda 4G03 Pro 1.0/1.0re/01.bin/04.03.01.53. Affected by this issue is some unknown functionality of the file /etc/www/pem/server.key of the component ECDSA P-256 Private Key Handler. This manipulation causes use of hard-coded cryptographic key . It is possible to initiate the attack remotely.
A vulnerability exists in the Tenda 4G03 Pro router in versions 1.0, 1.0re, 01.bin, and 04.03.01.53. The issue arises from an unencrypted ECDSA P-256 private key that is hard-coded and embedded in plaintext within the firmware. This key is located in the file /etc/www/pem/server.key and is accessible remotely. The vulnerability allows attackers to decrypt HTTPS traffic and conduct man-in-the-middle attacks on devices running this firmware. Additionally, other private keys compromising the device's firmware integrity verification were found embedded in the same firmware.
It is recommended to apply restrictive firewalling to mitigate this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://vuldb.com/submit/782053 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/vuln/355280 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/vuln/355280/cti | [email protected] | Permissions RequiredVDB Entry |
| https://www.tenda.com.cn/ | [email protected] | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-320 | Key Management Errors | [email protected] |
| CWE-321 | Use of Hard-coded Cryptographic Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| tenda 4g03 pro firmware | 04.03.01.53 |
CPE
Remediation
| |
| tenda 4g03 pro | 1.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 30, 2026 | Initial Analysis | [email protected] |
| Apr 5, 2026 | New CVE Received | [email protected] |