Vulnerability Description
A weakness has been identified in Tenda 4G03 Pro 1.0/1.0re/01.bin/04.03.01.53. Affected by this issue is some unknown functionality of the file /etc/www/pem/server.key of the component ECDSA P-256 Private Key Handler. This manipulation causes use of hard-coded cryptographic key . It is possible to initiate the attack remotely.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tenda | 4G03 Pro Firmware | 04.03.01.53 |
| Tenda | 4G03 Pro | 1.0 |
Related Weaknesses (CWE)
References
- https://vuldb.com/submit/782053Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/355280Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/355280/ctiPermissions RequiredVDB Entry
- https://www.tenda.com.cn/Product
FAQ
What is CVE-2026-5527?
CVE-2026-5527 is a vulnerability with a CVSS score of 5.3 (MEDIUM). A weakness has been identified in Tenda 4G03 Pro 1.0/1.0re/01.bin/04.03.01.53. Affected by this issue is some unknown functionality of the file /etc/www/pem/server.key of the component ECDSA P-256 Pri...
How severe is CVE-2026-5527?
CVE-2026-5527 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-5527?
Check the references section above for vendor advisories and patch information. Affected products include: Tenda 4G03 Pro Firmware, Tenda 4G03 Pro.