← Retour aux CVEs
CVE-2025-9828
LOW3.7
Description
A vulnerability was determined in Tenda CP6 11.10.00.243. The affected element is the function sub_2B7D04 of the component uhttp. Executing manipulation can lead to risky cryptographic algorithm. The attack may be launched remotely. This attack is characterized by high complexity. The exploitability is described as difficult. The exploit has been publicly disclosed and may be utilized.
Details CVE
Score CVSS v3.13.7
SeveriteLOW
Vecteur CVSSCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Vecteur d'attaqueNETWORK
ComplexiteHIGH
Privileges requisNONE
Interaction utilisateurNONE
Publie9/2/2025
Derniere modification4/29/2026
Sourcenvd
Observations honeypot0
Produits affectes
tenda:cp6tenda:cp6_firmware
Faiblesses (CWE)
CWE-310CWE-327
References
https://vuldb.com/?ctiid.322175(cna@vuldb.com)
https://vuldb.com/?id.322175(cna@vuldb.com)
https://vuldb.com/?submit.641566(cna@vuldb.com)
https://www.tenda.com.cn/(cna@vuldb.com)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.