Executive brief
Tenda CP3 is a wireless networking device used in home and small-office networks. A vulnerability allows an attacker to manipulate the WPA passphrase configuration parameter, resulting in the use of hard-coded credentials that could compromise wireless network security. An attacker can exploit this remotely without authentication, potentially allowing unauthorized network access.
Technical details
The vulnerability exists in the hostapd configuration handler within the custom-x/softap component of Tenda CP3 firmware version 27.5.57.101. The wpa_passphrase argument is not properly validated, permitting manipulation that leads to hard-coded credentials being used for wireless authentication. The attack is network-reachable and requires no prior authentication. Successful exploitation allows an attacker to gain unauthorized wireless network access using predictable credentials. A patch or firmware update from Tenda is recommended.
Affected products
- Tenda CP3 27.5.57.101
Timeline
- 2026-09-05: disclosed
- other: exploit disclosed publicly