← back
CVE-2025-46631

CVE-2025-46631

CVSS 6.5 MEDIUMEPSS 4.9%CWE-287
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.5EPSS 4.9%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
01 May 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Improper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to enable telnet access to the router's OS by sending a /goform/telnet web request.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Affected products
n/a · n/a

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →