Lack of access controls in the 'ate' management binary of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to perform unauthorized configuration changes for any router where 'ate' has been enabled by sending a crafted UDP packet
CVE ID: CVE-2025-46629
CVSS Base Severity: MEDIUM
CVSS Base Score: 6.5
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Vendor: n/a
Product: n/a
EPSS Score: 0.05% (probability of being exploited)
EPSS Percentile: 13.34% (scored less or equal to compared to others)
EPSS Date: 2025-05-30 (when was this score calculated)