CVE-2025-15371

7.8

Tenda · i24, 4G03 Pro, 4G05, 4G08, G0-8G-PoE, Nova MW5G, TEG5328F

Multiple Tenda networking devices contain hard-coded credentials within the Shadow File component, which can be exploited by local attackers to gain full system control.

Executive summary

A vulnerability in multiple Tenda networking devices allows local attackers to bypass authentication using hard-coded credentials, resulting in a total compromise of the affected hardware.

Vulnerability

The flaw, categorized under CWE-798 and CWE-259, involves the use of hard-coded credentials within the Shadow File component. Exploitation requires local access to the device to provide the Fireitup input, which triggers the authentication bypass.

Business impact

Successful exploitation leads to a total compromise of the affected networking equipment. Given the CVSS score of 7.8, this represents a high-severity risk, as an attacker with local access can gain administrative control, potentially leading to unauthorized network traffic interception, configuration changes, or the complete denial of service for critical infrastructure.

Remediation

Immediate Action: Since no official patch is currently identified, administrators should restrict physical and local access to the management interfaces of these devices to prevent unauthorized exploitation.

Proactive Monitoring: Monitor system logs for unauthorized login attempts or unexpected configuration changes originating from local interfaces.

Compensating Controls: Implement strict network segmentation to ensure that even if a device is compromised, the attacker cannot pivot to sensitive internal segments of the network.

Exploitation status

Public Exploit Available: Yes, a public exploit exists as documented in the referenced VulDB submission.

Analyst recommendation

The presence of hard-coded credentials represents a severe security design flaw that cannot be fully remediated through configuration changes alone. Organizations using the affected Tenda models should prioritize the replacement or isolation of these devices until the manufacturer releases a firmware update that removes the hard-coded credentials. Immediate restriction of local access is the primary defensive measure until a vendor-supplied patch is available.

More Tenda CVEs

Sources

Originally found and disclosed by vlun-1 (VulDB User), per the CVE Program record.