CVE-2025-9731: Tenda AC9 Administrative shadow hard-coded credentials
A vulnerability was determined in Tenda AC9 15.03.05.19. The impacted element is an unknown function of the file /etcro/shadow of the component Administrative Interface. This manipulation causes hard-coded credentials. It is possible to launch the attack on the local host. The attack's complexity is rated as high. The exploitability is regarded as difficult. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9731?
CVE-2025-9731 is considered a high severity vulnerability due to its exploitation potential through hard-coded credentials.
How do I fix CVE-2025-9731?
To fix CVE-2025-9731, ensure that you update the firmware of Tenda AC9 to the latest version available from the manufacturer.
What component is affected by CVE-2025-9731?
CVE-2025-9731 affects the Administrative Interface component of the Tenda AC9 router.
Can CVE-2025-9731 be exploited remotely?
CVE-2025-9731 requires local access for exploitation, making it a local privilege escalation vulnerability.
What impacts does CVE-2025-9731 have on security?
CVE-2025-9731 compromises the device's security by exposing hard-coded credentials that may allow unauthorized access.