CVE-2025-52054: Medium severity Tenda AC8 AC1200 Dual-band Gigabit Wireless Router vulnerability
An issue was discovered in Tenda AC8 v4.0 AC1200 Dual-band Gigabit Wireless Router AC8v4.0 Firmware 16.03.33.05. The root password of the device is calculated with a static string and the last two octets of the MAC address of the device. This allows an unauthenticated attacker to authenticate with network services on the device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52054?
CVE-2025-52054 is considered a critical vulnerability due to its potential for unauthorized access to the device.
How do I fix CVE-2025-52054?
To fix CVE-2025-52054, users should update their Tenda AC8 AC1200 firmware to the latest version provided by the manufacturer.
What type of attack does CVE-2025-52054 enable?
CVE-2025-52054 enables unauthenticated attackers to gain root access to the Tenda AC8 router.
What devices are affected by CVE-2025-52054?
CVE-2025-52054 affects the Tenda AC8 v4.0 AC1200 Dual-band Gigabit Wireless Router with firmware version 16.03.33.05.
Is user intervention required to exploit CVE-2025-52054?
No, user intervention is not required to exploit CVE-2025-52054, making it particularly dangerous.