Vulnerability Description
An issue was discovered on Tenda RX2 Pro 16.03.30.14 devices. Improper network isolation between the guest Wi-Fi network and other network interfaces on the router allows an attacker (who is authenticated to the guest Wi-Fi) to access resources on the router and/or resources and devices on other networks hosted by the router by configuring a static IP address (within the non-guest subnet) on their host.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tenda | Rx2 Pro Firmware | 16.03.30.14 |
| Tenda | Rx2 Pro | - |
Related Weaknesses (CWE)
References
- https://blog.uturn.dev/#/writeups/iot-village/tenda-w18e/README?id=cve-2024-4643ExploitThird Party Advisory
- https://www.tendacn.com/us/default.htmlProduct
FAQ
What is CVE-2025-46635?
CVE-2025-46635 is a vulnerability with a CVSS score of 7.1 (HIGH). An issue was discovered on Tenda RX2 Pro 16.03.30.14 devices. Improper network isolation between the guest Wi-Fi network and other network interfaces on the router allows an attacker (who is authentic...
How severe is CVE-2025-46635?
CVE-2025-46635 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-46635?
Check the references section above for vendor advisories and patch information. Affected products include: Tenda Rx2 Pro Firmware, Tenda Rx2 Pro.