Cyber Posture

CVE-2024-46433

HighPublic PoC

Published: 10 February 2025

Published
10 February 2025
Modified
25 March 2025
KEV Added
Patch
CVSS Score 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0097 76.7th percentile
Risk Priority 18 60% EPSS · 20% KEV · 20% CVSS

Description

A default credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access the web management portal using the default rzadmin account with administrative privileges.

Security Summary

CVE-2024-46433 is a default credentials vulnerability (CWE-798) in the Tenda W18E router firmware version V16.01.0.8(1625). It enables unauthenticated remote attackers to access the web management portal using the default "rzadmin" account, which possesses administrative privileges. The issue carries a CVSS v3.1 base score of 8.8 (AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and was published on 2025-02-10.

An attacker with access to the adjacent network can exploit this vulnerability with low complexity and no required privileges or user interaction. Upon logging in with the default credentials, the attacker gains administrative control over the device, potentially allowing high-impact confidentiality, integrity, and availability compromises, such as modifying configurations, extracting sensitive data, or disrupting network operations.

Mitigation details are available in the security research advisory at https://reddassolutions.com/blog/tenda_w18e_security_research.

Details

CWE(s)
CWE-798

Affected Products

tenda
w18e firmware
16.01.0.8\(1625\)

References