CVE-2025-46632: Tenda RX2 Pro Firmware

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Initialization vector (IV) reuse in the web management portal of the Tenda RX2 Pro 16.03.30.14 may allow an attacker to discern information about or more easily decrypt encrypted messages between client and server.

Affected products

  • Tenda RX2 Pro Firmware: version 16.03.30.14 only

Published 2025-05-01. Last modified 2026-06-17.