Tenda RP3 Pro Firmware Update force_upgrade.sh hard-coded password
Vulnerability Description
A flaw has been found in Tenda RP3 Pro up to 22.5.7.93. This impacts an unknown function of the file force_upgrade.sh of the component Firmware Update Handler. Executing manipulation of the argument current_force_upgrade_pwd can lead to use of hard-coded password. The attack can only be executed locally. The exploit has been published and may be used.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-11666
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- IOT_Res (VulDB User)
References
More from Tenda
View All →Affected Vendor
Tenda
View all reports →