CVE-2025-46626: Tenda RX2 Pro Firmware
High severity, CVSS 7.3. EPSS: 0.2% chance of exploitation in the next 30 days.
Reuse of a static AES key and initialization vector for encrypted traffic to the 'ate' management service of the Tenda RX2 Pro 16.03.30.14 allows an attacker to decrypt, replay, and/or forge traffic to the service.
Affected products
- Tenda RX2 Pro Firmware: version 16.03.30.14 only
Published 2025-05-01. Last modified 2026-06-17.