CVE-2025-46630: Tenda RX2 Pro Firmware

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Improper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to enable 'ate' (a remote system management binary) by sending a /goform/ate web request.

Affected products

  • Tenda RX2 Pro Firmware: version 16.03.30.14 only

Published 2025-05-01. Last modified 2026-06-17.