CVE-2025-9828
⚪ Do wiadomości
Manipulacja w Tenda CP6 umożliwia wykorzystanie ryzykownego algorytmu kryptograficznego.
CVSS
3.7
EPSS
0.3%
Exploit
poc
Vendor
tenda
Opis źródłowy (NVD)
A vulnerability was determined in Tenda CP6 11.10.00.243. The affected element is the function sub_2B7D04 of the component uhttp. Executing manipulation can lead to risky cryptographic algorithm. The attack may be launched remotely. This attack is characterized by high complexity. The exploitability is described as difficult. The exploit has been publicly disclosed and may be utilized.
exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 3.7 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.3% |
| Opublikowano (NVD) | 2025-09-02 17:15:36 UTC |
| Ostatnia modyfikacja (NVD) | 2026-09-30 23:10:00 UTC |
Referencje
- https://github.com/IOTRes/IOT_Firmware_Update/blob/main/Tenda/CP6.md ([email protected]) [Exploit, Third Party Advisory]
- https://vuldb.com/?ctiid.322175 ([email protected]) [Permissions Required, VDB Entry]
- https://vuldb.com/?id.322175 ([email protected]) [Third Party Advisory, VDB Entry]
- https://vuldb.com/?submit.641566 ([email protected]) [Third Party Advisory, VDB Entry]
- https://www.tenda.com.cn/ ([email protected]) [Product]