← volver
CVE-2025-9731

Tenda AC9 Administrative shadow hard-coded credentials

CVSS 2 LOWEPSS 0.1%CWE-259CWE-798
Vexday Risk Score
8Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 2EPSS 0.1%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
31 ago 2025Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
A vulnerability was determined in Tenda AC9 15.03.05.19. The impacted element is an unknown function of the file /etc_ro/shadow of the component Administrative Interface. This manipulation causes hard-coded credentials. It is possible to launch the attack on the local host. The attack's complexity is rated as high. The exploitability is regarded as difficult. The exploit has been publicly disclosed and may be utilized.
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
Productos afectados
Tenda · AC9

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →