Junglewise Threat Intelligence

CVE-2026-5527: Tenda 4G03 Pro hard-coded cryptographic key in ECDSA handler

CVE-2026-5527 · Severity: medium · CVSS 5.3 · Published 2026-04-05

Vendors: Tenda.

Executive brief

A security vulnerability has been identified in the Tenda 4G03 Pro, a wireless router used for mobile internet connectivity. The device uses a hard-coded security key for its encrypted communications, which could allow an unauthorized person to intercept or decrypt sensitive traffic. This could lead to the exposure of private data transmitted through the router.

Technical details

A vulnerability exists in the Tenda 4G03 Pro firmware (versions 1.0, 1.0re, 01.bin, and 04.03.01.53) due to the use of a hard-coded cryptographic key. Specifically, the ECDSA P-256 Private Key Handler utilizes a static private key stored in /etc/www/pem/server.key. An attacker can exploit this by obtaining the fixed key from the firmware to perform man-in-the-middle attacks or decrypt SSL/TLS traffic intended for the device's web interface. The attack can be initiated remotely over the network without requiring authentication.

Affected products

  • Tenda 4G03 Pro 1.0, 1.0re, 01.bin, 04.03.01.53

Timeline

  • 2026-04-05: disclosed: Initial disclosure date
  • 2026-04-05: advisory: NVD publication date

References

Related threats