CVE-2025-11666Medium· 6.7▾ SunlitA flaw has been found in Tenda RP3 Pro up to 22.5.7.93. This impacts an unknown function of the file force_upgrade.sh of the component Firmware Update Handler. Executing manipulation of the argument current_force_upgrade_pwd can lead to …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 36.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
A flaw has been found in Tenda RP3 Pro up to 22.5.7.93. This impacts an unknown function of the file force_upgrade.sh of the component Firmware Update Handler. Executing manipulation of the argument current_force_upgrade_pwd can lead to use of hard-coded password. The attack can only be executed locally. The exploit has been published and may be used.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-9806Low· 1.9A vulnerability was determined in Tenda F1202 1.2.0.9/1.2.0.14/1.2.0.20
CVE-2025-6139Low· 3.9A vulnerability, which was classified as problematic, has been found in TOTOLINK T10 4.1.8cu.5207
CVE-2026-97877High· 7.3A vulnerability was determined in zhistaredu StarTraining up to 3.8.1
CVE-2026-86150Medium· 4.1A security vulnerability has been detected in Tenda CP3 27.5.57.101
CVE-2025-13221Medium· 5.3A weakness has been identified in Intelbras UnniTI 24.07.11
CVE-2025-13187Medium· 5.3A security vulnerability has been detected in Intelbras ICIP 2.0.20