CVE-2025-9828 – Tenda CP6 Remote Difficult Cryptographic Algorithm Vulnerability

The following table lists the changes that have been made to the
CVE-2025-9828 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Sep. 02, 2025

    Action Type Old Value New Value
    Added Description A vulnerability was determined in Tenda CP6 11.10.00.243. The affected element is the function sub_2B7D04 of the component uhttp. Executing manipulation can lead to risky cryptographic algorithm. The attack may be launched remotely. This attack is characterized by high complexity. The exploitability is described as difficult. The exploit has been publicly disclosed and may be utilized.
    Added CVSS V4.0 AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    Added CVSS V3.1 AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
    Added CVSS V2 (AV:N/AC:H/Au:N/C:N/I:P/A:N)
    Added CWE CWE-310
    Added CWE CWE-327
    Added Reference https://github.com/IOTRes/IOT_Firmware_Update/blob/main/Tenda/CP6.md
    Added Reference https://vuldb.com/?ctiid.322175
    Added Reference https://vuldb.com/?id.322175
    Added Reference https://vuldb.com/?submit.641566
    Added Reference https://www.tenda.com.cn/
Share the Post:

Related Posts