Lack of input validation/sanitization in the 'ate' management service in the Tenda RX2 Pro 16.03.30.14 allows an unauthorized remote attacker to gain root shell access to the device by sending a crafted UDP packet to the 'ate' service when it is enabled. Authentication is not needed.
2025-05-01T20:15:38.510
2025-05-27T14:24:08.060
Analyzed
CVSSv3.1: 7.3 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | tenda | rx2_pro_firmware | 16.03.30.14 | Yes |
Hardware | tenda | rx2_pro | - | No |