← volver
CVE-2025-9828

Tenda CP6 uhttp sub_2B7D04 risky encryption

CVSS 6.3 MEDIUMEPSS 0.3%CWE-310CWE-327
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 6.3EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch referenciado
Ciclo de vida
02 sep 2025Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
A vulnerability was determined in Tenda CP6 11.10.00.243. The affected element is the function sub_2B7D04 of the component uhttp. Executing manipulation can lead to risky cryptographic algorithm. The attack may be launched remotely. This attack is characterized by high complexity. The exploitability is described as difficult. The exploit has been publicly disclosed and may be utilized.
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
Productos afectados
Tenda · CP6

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →