Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-25467 | A vulnerability was found in Tenda AC10 16.03.10.13. Affected is an unknown function of the file /etc_ro/shadow of the component MD5 Hash Handler. Performing manipulation results in hard-coded credentials. The attack needs to be approached locally. A high degree of complexity is needed for the attack. The exploitability is told to be difficult. The exploit has been made public and could be used. |
Mon, 25 Aug 2025 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tenda ac10 Firmware
|
|
| CPEs | cpe:2.3:h:tenda:ac10:4.0:*:*:*:*:*:*:* cpe:2.3:o:tenda:ac10_firmware:16.03.10.13:*:*:*:*:*:*:* |
|
| Vendors & Products |
Tenda ac10 Firmware
|
Sat, 23 Aug 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tenda
Tenda ac10 |
|
| Vendors & Products |
Tenda
Tenda ac10 |
Thu, 21 Aug 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 21 Aug 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in Tenda AC10 16.03.10.13. Affected is an unknown function of the file /etc_ro/shadow of the component MD5 Hash Handler. Performing manipulation results in hard-coded credentials. The attack needs to be approached locally. A high degree of complexity is needed for the attack. The exploitability is told to be difficult. The exploit has been made public and could be used. | |
| Title | Tenda AC10 MD5 Hash shadow hard-coded credentials | |
| Weaknesses | CWE-259 CWE-798 |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-08-21T17:31:37.142Z
Reserved: 2025-08-21T06:06:44.302Z
Link: CVE-2025-9309
Updated: 2025-08-21T17:23:00.661Z
Status : Analyzed
Published: 2025-08-21T17:15:33.277
Modified: 2026-04-29T01:00:01.613
Link: CVE-2025-9309
No data.
OpenCVE Enrichment
Updated: 2025-08-23T10:55:37Z
EUVD