CVE-2025-9309: Tenda AC10 MD5 Hash shadow hard-coded credentials
A vulnerability was found in Tenda AC10 16.03.10.13. Affected is an unknown function of the file /etcro/shadow of the component MD5 Hash Handler. Performing manipulation results in hard-coded credentials. The attack needs to be approached locally. A high degree of complexity is needed for the attack. The exploitability is told to be difficult. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9309?
CVE-2025-9309 has a high severity due to the potential for unauthorized access through hard-coded credentials.
How do I fix CVE-2025-9309?
To fix CVE-2025-9309, update the Tenda AC10 firmware to the latest version provided by the vendor.
What impact does CVE-2025-9309 have on Tenda AC10 users?
CVE-2025-9309 allows local attackers to gain access to sensitive credentials, compromising the device's security.
Is CVE-2025-9309 exploitable remotely?
No, CVE-2025-9309 requires local access to exploit the vulnerability.
What component is affected by CVE-2025-9309?
CVE-2025-9309 affects the MD5 Hash Handler component in the Tenda AC10 device.