Local Credential Vulnerability in Tenda AC10 Router
CVE-2025-9309
Key Information:
Badges
What is CVE-2025-9309?
A vulnerability has been identified in the Tenda AC10 router, specifically within an unknown function related to the MD5 Hash Handler located in the /etc_ro/shadow file. This flaw allows an attacker with local access to exploit hard-coded credentials, which could lead to unauthorized access and potential compromise of the device. While the attack requires a high level of complexity and local access, the exploit details have been made public, highlighting the necessity for users to secure their devices against this potential threat.
Affected Version(s)
AC10 16.03.10.13
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved