CVE-2025-46625 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Lack of input validation/sanitization in the 'setLanCfg' API endpoint in httpd in the Tenda RX2 Pro 16.03.30.14 allows a remote attacker that is authorized to t…
High CVSS: 8.8

CVE-2025-46625

Lack of input validation/sanitization in the 'setLanCfg' API endpoint in httpd in the Tenda RX2 Pro 16.03.30.14 allows a remote attacker that is authorized to the web management portal to gain root shell access to the device by sending a crafted web request. This is persistent because the command injection is saved in the configuration of the device.
Vendor
Tenda
Product
Rx2 Pro Firmware
CWE
CWE-77
Yayın Tarihi
2025-05-01 20:15:38
Güncelleme
2025-05-27 14:22:39
Source Identifier
cve@mitre.org
KEV Date Added
-

Kategoriler

Referanslar