CVE-2025-46626: Tenda RX2 Pro Firmware

High severity, CVSS 7.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Reuse of a static AES key and initialization vector for encrypted traffic to the 'ate' management service of the Tenda RX2 Pro 16.03.30.14 allows an attacker to decrypt, replay, and/or forge traffic to the service.

Affected products

  • Tenda RX2 Pro Firmware: version 16.03.30.14 only

Published 2025-05-01. Last modified 2026-06-17.