A researcher accidentally bought the wrong Tenda router (AC10V6 instead of the intended model) while investigating a known backdoor CVE, then proceeded to find exploits in it anyway. By combining CVE-2025-9090 (a Telnet activation exploit) and CVE-2025-52054 (a root password derivation method using a static string and MAC address octets), they gained root access. The static string needed for password calculation was unknown for this model, but Tenda helpfully printed it to the UART serial output. Probing the UART pins revealed the pre-Base64 password, which granted full root Telnet access and exposed the previously encrypted firmware along with its decryption keys.
48 Impressions