Use of weak credentials in the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated attacker to authenticate to the telnet service by calculating the root password based on easily-obtained device information. The password is based on the last two digits/octets of the MAC address.
2025-05-01T20:15:38.350
2025-05-27T14:23:32.547
Analyzed
CVSSv3.1: 8.2 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | tenda | rx2_pro_firmware | 16.03.30.14 | Yes |
| Hardware | tenda | rx2_pro | - | No |