---
id: CVE-2025-11666
title: A flaw has been found in Tenda RP3 Pro up to 22.5.7.93
summary: >-
  A flaw has been found in Tenda RP3 Pro up to 22.5.7.93. This impacts an
  unknown function of the file force_upgrade.sh of the component Firmware Update
  Handler. Executing manipulation of the argument current_force_upgrade_pwd can
  lead to …
severity: medium
cvss: 6.7
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-255
  - CWE-259
published: '2025-10-13'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T12:10:00.217'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11666'
references:
  - url: 'https://github.com/IOTRes/IOT_Firmware_Update/blob/main/Tenda/RP3.md'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.328085'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.328085'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.673128'
    label: cna@vuldb.com
  - url: 'https://www.tenda.com.cn/'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00158
epssPercentile: 0.04309
ingestedAt: '2026-10-08T11:31:27.349Z'
---

## Overview

A flaw has been found in Tenda RP3 Pro up to 22.5.7.93. This impacts an unknown function of the file force_upgrade.sh of the component Firmware Update Handler. Executing manipulation of the argument current_force_upgrade_pwd can lead to use of hard-coded password. The attack can only be executed locally. The exploit has been published and may be used.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
