CVE-2025-70802: High severity Tenda G1V3.1si Firmware vulnerability
Published Mar 10, 2026
·Updated
Tenda G1V3.1si V16.01.7.8 Firmware V16.01.7.8 was discovered to contain a hardcoded password vulnerability in /etcro/shadow, which allows attackers to log in as root.
Affected Software
3 affected components
Tenda G1V3.1si Firmware
All of the following
Tenda G1 Firmware=16.01.7.8
Tenda G1=3.1
Event History
Mar 10, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-70802?
The severity of CVE-2025-70802 is considered high due to the existence of a hardcoded password vulnerability that allows for root access.
2
How do I fix CVE-2025-70802?
To fix CVE-2025-70802, you should update the Tenda G1V3.1si firmware to the latest version that addresses this vulnerability.
3
Who is affected by CVE-2025-70802?
CVE-2025-70802 affects users of the Tenda G1V3.1si Firmware version 16.01.7.8.
4
What type of vulnerability is CVE-2025-70802?
CVE-2025-70802 is classified as a hardcoded password vulnerability.
5
What can an attacker do with CVE-2025-70802?
An attacker exploiting CVE-2025-70802 can log in as root, potentially gaining full control over the affected device.