CVE-2026-5527: Tenda 4g03 Pro Firmware

Medium severity, CVSS 5.3. EPSS: 0.6% chance of exploitation in the next 30 days.

A weakness has been identified in Tenda 4G03 Pro 1.0/1.0re/01.bin/04.03.01.53. Affected by this issue is some unknown functionality of the file /etc/www/pem/server.key of the component ECDSA P-256 Private Key Handler. This manipulation causes use of hard-coded cryptographic key . It is possible to initiate the attack remotely.

Affected products

  • Tenda 4g03 Pro Firmware: version 04.03.01.53 only

Published 2026-04-05. Last modified 2026-07-24.