Use of weak credentials in the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated attacker to authenticate to the telnet service by calculating the root password based on easily-obtained device information. The password is based on the last two digits/octets of the MAC address.
                
            References
                    | Link | Resource | 
|---|---|
| https://blog.uturn.dev/#/writeups/iot-village/tenda-rx2pro/README?id=cve-2025-46627-calculated-os-root-password | Third Party Advisory Exploit | 
| https://www.tendacn.com/us/default.html | Product | 
Configurations
                    Configuration 1 (hide)
| AND | 
 
 | 
History
                    27 May 2025, 14:23
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-05-01 20:15
Updated : 2025-05-27 14:23
NVD link : CVE-2025-46627
Mitre link : CVE-2025-46627
CVE.ORG link : CVE-2025-46627
JSON object : View
Products Affected
                tenda
- rx2_pro
- rx2_pro_firmware
CWE
                
                    
                        
                        CWE-922
                        
            Insecure Storage of Sensitive Information
