CVE-2025-46632
MEDIUMDescription
Initialization vector (IV) reuse in the web management portal of the Tenda RX2 Pro 16.03.30.14 may allow an attacker to discern information about or more easily decrypt encrypted messages between client and server.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| tenda | rx2_pro_firmware |
| tenda | rx2_pro |
References
Frequently Asked Questions
What is CVE-2025-46632? +
How severe is CVE-2025-46632? +
What products are affected by CVE-2025-46632? +
How do I check if I'm vulnerable to CVE-2025-46632? +
Related Vulnerabilities
Due to Nonce reuse, attackers can perform reply attack or decrypt captured packets.
hpke-js is a Hybrid Public Key Encryption (HPKE) module built on top of Web Cryptography API. Prior to version 1.7.5, …
The AES key utilized in the pairing process between a lock using Sciener firmware and a wireless keypad is not …
In hostapd 2.10 and earlier, the PKEX code remains active even after a successful PKEX association. An attacker that successfully …
Astro is a web framework. Astro versions prior to 6.1.10 used AES-GCM encryption to protect the confidentiality and integrity of …
netty-incubator-codec-ohttp is the OHTTP implementation for netty. BoringSSLAEADContext keeps track of how many OHTTP responses have been sent and uses …