CVE-2025-70798: Tenda i24 Firmware

High severity, CVSS 8.4. EPSS: 0.2% chance of exploitation in the next 30 days.

Tenda i24V3.0si V3.0.0.5 Firmware V3.0.0.5 was discovered to contain a hardcoded password vulnerability in /etc_ro/shadow, which allows attackers to log in as root.

Affected products

  • Tenda i24 Firmware: version 3.0.0.5 only

Published 2026-03-10. Last modified 2026-06-17.