CVE-2025-15371
7.8Tenda · i24, 4G03 Pro, 4G05, 4G08, G0-8G-PoE, Nova MW5G, TEG5328F
Multiple Tenda networking devices contain hard-coded credentials within the Shadow File component, which can be exploited by local attackers to gain full system control.
Executive summary
A vulnerability in multiple Tenda networking devices allows local attackers to bypass authentication using hard-coded credentials, resulting in a total compromise of the affected hardware.
Vulnerability
The flaw, categorized under CWE-798 and CWE-259, involves the use of hard-coded credentials within the Shadow File component. Exploitation requires local access to the device to provide the Fireitup input, which triggers the authentication bypass.
Business impact
Successful exploitation leads to a total compromise of the affected networking equipment. Given the CVSS score of 7.8, this represents a high-severity risk, as an attacker with local access can gain administrative control, potentially leading to unauthorized network traffic interception, configuration changes, or the complete denial of service for critical infrastructure.
Remediation
Immediate Action: Since no official patch is currently identified, administrators should restrict physical and local access to the management interfaces of these devices to prevent unauthorized exploitation.
Proactive Monitoring: Monitor system logs for unauthorized login attempts or unexpected configuration changes originating from local interfaces.
Compensating Controls: Implement strict network segmentation to ensure that even if a device is compromised, the attacker cannot pivot to sensitive internal segments of the network.
Exploitation status
Public Exploit Available: Yes, a public exploit exists as documented in the referenced VulDB submission.
Analyst recommendation
The presence of hard-coded credentials represents a severe security design flaw that cannot be fully remediated through configuration changes alone. Organizations using the affected Tenda models should prioritize the replacement or isolation of these devices until the manufacturer releases a firmware update that removes the hard-coded credentials. Immediate restriction of local access is the primary defensive measure until a vendor-supplied patch is available.
More Tenda CVEs
Sources
Originally found and disclosed by vlun-1 (VulDB User), per the CVE Program record.
- VDB-339075 | Tenda i24 Shadow File hard-coded credentials Vulnerability database entry
- VDB-339075 | CTI Indicators (IOB, IOC, TTP, IOA)
- Submit #727155 | Tenda Tenda i24v3.0 V3.0.0.8(4008) V3.0.0.8(4008) Hard-coded Credentials Third-party advisory
- Submit #727283 | Tenda 4G03ProV1.0re V04.03.01.49 Hard-coded Credentials (Duplicate) Third-party advisory
- Submit #727284 | Tenda 4G05V1.0re V04.05.01.15 Hard-coded Credentials (Duplicate) Third-party advisory
- Submit #727285 | Tenda 4G08V1.0re V04.08.01.28 Hard-coded Credentials (Duplicate) Third-party advisory
- Submit #727302 | Tenda G0-8G-PoEV2.0si V16.01.8.5 Hard-coded Credentials (Duplicate) Third-party advisory
- Submit #727305 | Tenda MW5GV1.0re V1.0.0.35 Hard-coded Credentials (Duplicate) Third-party advisory