Improper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to enable telnet access to the router's OS by sending a /goform/telnet web request.
                
            References
                    | Link | Resource | 
|---|---|
| https://blog.uturn.dev/#/writeups/iot-village/tenda-rx2pro/README?id=cve-2025-46631-enable-telnet-unauthenticated-through-httpd | Third Party Advisory Exploit | 
| https://www.tendacn.com/us/default.html | Product | 
Configurations
                    Configuration 1 (hide)
| AND | 
 
 | 
History
                    27 May 2025, 14:24
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-05-01 20:15
Updated : 2025-05-27 14:24
NVD link : CVE-2025-46631
Mitre link : CVE-2025-46631
CVE.ORG link : CVE-2025-46631
JSON object : View
Products Affected
                tenda
- rx2_pro
- rx2_pro_firmware
CWE
                
                    
                        
                        CWE-287
                        
            Improper Authentication
