CVE detail
CVE-2025-11666
A flaw has been found in Tenda RP3 Pro up to 22.5.7.93. This impacts an unknown function of the file force_upgrade.sh of the component Firmware Update Handler. Executing manipulation of the argument current_force_upgrade_pwd can lead to use of hard-coded password. The attack can only be executed locally. The exploit has been published and may be used.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 17.9 · diversity 11.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
5 source links · newest first
- https://www.tenda.com.cn/www.tenda.com.cn
No excerpt available.
Third Party Advisorywww.tenda.com.cnOct 13, 2025, 7:15 AM - https://vuldb.com/?submit.673128vuldb.com
No excerpt available.
Exploitvuldb.comOct 13, 2025, 7:15 AM - https://vuldb.com/?id.328085vuldb.com
No excerpt available.
Exploitvuldb.comOct 13, 2025, 7:15 AM - https://vuldb.com/?ctiid.328085vuldb.com
No excerpt available.
Exploitvuldb.comOct 13, 2025, 7:15 AM No excerpt available.
Exploitgithub.comOct 13, 2025, 7:15 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-11552CVSS 5.5 · Medium
A vulnerability has been found in SourceCodester Onlne Examination & Learning Management System and Syllabus-aligned Learning Management and Examination System 1.0. Affected by th…
- CVE-2026-11515CVSS 5.5 · Medium
A vulnerability has been found in SourceCodester Barangay Resident Profiling and Information Management System 1.0. The impacted element is an unknown function of the file passswo…
- CVE-2025-11649CVSS 6.4 · Medium
A vulnerability was found in Tomofun Furbo 360 and Furbo Mini. The affected element is an unknown function of the component Root Account Handler. Performing manipulation results i…
- CVE-2025-11284CVSS 5.5 · Medium
A vulnerability has been found in Zytec Dalian Zhuoyun Technology Central Authentication Service 3. Affected by this vulnerability is an unknown functionality of the file /index.p…
- CVE-2025-9725CVSS 1.1 · Low
A vulnerability was identified in Cudy LT500E up to 2.3.12. Affected is an unknown function of the file /squashfs-root/etc/shadow of the component Web Interface. The manipulation…
- CVE-2025-7577CVSS 2.9 · Low
A vulnerability was found in Teledyne FLIR FB-Series O and FLIR FH-Series ID 1.3.2.16. It has been classified as problematic. This affects an unknown part. The manipulation leads…