CVE-2025-46629: Tenda RX2 Pro Firmware

Medium severity, CVSS 6.5. EPSS: 0.9% chance of exploitation in the next 30 days.

Lack of access controls in the 'ate' management binary of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to perform unauthorized configuration changes for any router where 'ate' has been enabled by sending a crafted UDP packet

Affected products

  • Tenda RX2 Pro Firmware: version 16.03.30.14 only

Published 2025-05-01. Last modified 2026-06-17.