Command Injection Vulnerability in Tenda RX2 Pro by Tenda
CVE-2025-46628
7.3HIGH
What is CVE-2025-46628?
A critical input validation flaw in the 'ate' management service of the Tenda RX2 Pro 16.03.30.14 permits remote attackers to exploit the device. By sending a specially crafted UDP packet to the enabled 'ate' service, attackers can gain root shell access without the need for authentication, leading to potential unauthorized control over the device.