Security Advisory

CVE-2025-52364

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-07-09 00:00:00
Last updated 2025-07-14 17:04:02
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Insecure Permissions vulnerability in Tenda CP3 Pro Firmware V22.5.4.93 allows the telnet service (telnetd) by default at boot via the initialization script /etc/init.d/eth.sh. This allows remote attackers to connect to the device s shell over the network, potentially without authentication if default or weak credentials are present