CVE-2025-14636 is a security flaw in Tenda AX9 22.03.01.46 firmware, specifically within the image_check function of the httpd component, leading to the use of a weak hash. This vulnerability has a low CVSS score of 3.7, indicating a difficult attack complexity and remote exploitability, with a potential impact of low integrity. While an exploit has been publicly released, there is no evidence of active exploitation, and it lacks coverage in Metasploit, Nuclei, or ExploitDB, with minimal community discussion or media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
22.03.01.46CPE matchmatch criteria | cpe:2.3:o:tenda:ax9_firmware:22.03.01.46:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.