---
id: CVE-2025-9828
title: A vulnerability was determined in Tenda CP6 11.10.00.243
summary: >-
  A vulnerability was determined in Tenda CP6 11.10.00.243. The affected element
  is the function sub_2B7D04 of the component uhttp. Executing manipulation can
  lead to risky cryptographic algorithm. The attack may be launched remotely.
  This…
severity: low
cvss: 3.7
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-310
  - CWE-327
vendor: tenda
product: cp6_firmware
affected:
  - cp6_firmware = 11.10.00.243
published: '2025-09-02'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-9828'
references:
  - url: 'https://github.com/IOTRes/IOT_Firmware_Update/blob/main/Tenda/CP6.md'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.322175'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.322175'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.641566'
    label: cna@vuldb.com
  - url: 'https://www.tenda.com.cn/'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00342
epssPercentile: 0.25231
ingestedAt: '2026-09-30T23:29:32.353Z'
---

## Overview

A vulnerability was determined in Tenda CP6 11.10.00.243. The affected element is the function sub_2B7D04 of the component uhttp. Executing manipulation can lead to risky cryptographic algorithm. The attack may be launched remotely. This attack is characterized by high complexity. The exploitability is described as difficult. The exploit has been publicly disclosed and may be utilized.

## Affected

- `cp6_firmware = 11.10.00.243`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
