CVE-2025-46628
Lack of input validation/sanitization in the 'ate' management service in the Tenda RX2 Pro 16.03.30.14 allows an unauthorized remote attacker to gain root shell access to the device by sending a crafted UDP packet to the 'ate' service when it is enabled. Authentication is not needed.
Vendor
Product
CWE
Yayın Tarihi
2025-05-01 20:15:38
Güncelleme
2025-05-27 14:24:08
Source Identifier
cve@mitre.org
KEV Date Added
-