Tenda RX2 Pro
cpe:2.3:h:tenda:rx2_pro:*:*:*:*:*:*:*, +1 more
- 16.03.30.14
A vulnerability exists in the Tenda RX2 Pro Wi-Fi 6 router, specifically in version 16.03.30.14, due to the cleartext transmission of sensitive information through the web management portal. This flaw may allow an unauthenticated attacker to intercept and collect credentials from unencrypted traffic, enabling access to the management portal. Although the router implements encryption, it only activates after the user has transmitted a hashed password in cleartext. The intercepted hash can be replayed to authenticate.
Exploitation of this vulnerability could lead to unauthorized access to the router's web management portal, allowing an attacker to authenticate using intercepted credentials.
The vulnerability can be reproduced by observing the authentication process through a network traffic analysis tool like Wireshark. The transmitted data will include the user's password hash in cleartext, which can be captured and reused to gain access to the web management portal.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.