AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-46627

HIGH · CVSS 8.2 EPSS 0.41%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-05-01 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.2. Exploitation may require the attacker to be authenticated.

CVE
CVE-2025-46627
Severity
HIGH
CVSS
8.2
EPSS
0.41%

Original NVD Description

Use of weak credentials in the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated attacker to authenticate to the telnet service by calculating the root password based on easily-obtained device information. The password is based on the last two digits/octets of the MAC address.

Related CVEs

Other vulnerabilities affecting the same vendor(s)