MEDIUM
Tenda AX9 httpd image_check weak hash
Published Dec 13, 2025
6.3
MEDIUMCVSS 4.0
EPSS 0.29%
Description
A security flaw has been discovered in Tenda AX9 22.03.01.46. This affects the function image_check of the component httpd. The manipulation results in use of weak hash. It is possible to launch the attack remotely. A high complexity level is associated with this attack. It is indicated that the exploitability is difficult. The exploit has been released to the public and may be used for attacks.
Affected products
-
Affected
- 22.03.01.46
AND
- 22.03.01.46
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-203271 Advisory
- https://github.com/IOTRes/IOT_Firmware_Update/blob/main/Tenda/AX9_Inte.md exploitpatchThird Party Advisory
- https://vuldb.com/?ctiid.336361 signaturepermissions-requiredPermissions RequiredVDB Entry
- https://vuldb.com/?id.336361 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
- https://vuldb.com/?submit.707213 third-party-advisoryThird Party AdvisoryVDB Entry
- https://www.tenda.com.cn/ product
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-203271 | Advisory | |
| https://github.com/IOTRes/IOT_Firmware_Update/blob/main/Tenda/AX9_Inte.md | exploitpatchThird Party Advisory | |
| https://vuldb.com/?ctiid.336361 | signaturepermissions-requiredPermissions RequiredVDB Entry | |
| https://vuldb.com/?id.336361 | vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?submit.707213 | third-party-advisoryThird Party AdvisoryVDB Entry | |
| https://www.tenda.com.cn/ | product |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Dec 13, 2025
Updated Feb 24, 2026
Reserved Dec 13, 2025
Link CVE-2025-14636
CISA Vulnrichment
Updated Dec 15, 2025
Red Hat
No data
GitHub
No data