Tenda RX2 Pro Cleartext Transmission of Symmetric AES Key Vulnerability

Vulnerability

A vulnerability exists in the Tenda RX2 Pro router's web management portal, specifically in version 16.03.30.14. The issue arises from the cleartext transmission of sensitive information, allowing an attacker to intercept and decrypt traffic between the client and server. This is possible because the symmetric AES key used for encryption is sent in cleartext after successful authentication. The initialization vector (IV) used in the encryption process is always the same, further compromising the security of the transmission.

Impact

Exploitation of this vulnerability allows for the interception and decryption of encrypted traffic between the client and the Tenda RX2 Pro router's web management portal.

Reproduction

After authenticating with the web management portal, the AES key is transmitted in cleartext. This key can be intercepted and used to decrypt any collected encrypted traffic. The IV used in the encryption is static and known, allowing for straightforward decryption of the intercepted data.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
2.5
exploitability
7.2
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.