CVE-2025-46635
7.1
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Exploitability: 2.8 / Impact: 4.2
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)
Description
An issue was discovered on Tenda RX2 Pro 16.03.30.14 devices. Improper network isolation between the guest Wi-Fi network and other network interfaces on the router allows an attacker (who is authenticated to the guest Wi-Fi) to access resources on the router and/or resources and devices on other networks hosted by the router by configuring a static IP address (within the non-guest subnet) on their host.
Affected (1)
Products: Tenda: Rx2 Pro Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 16.03.30.14 |
| Running on/with | Platform Versions |
|---|---|
Tenda Rx2 Pro | All versions |
References (2)
Source: cve@mitre.org
ExploitThird Party Advisory
Timeline
No history available yet.