CVE-2025-5864 is a low-severity vulnerability affecting Tenda TDSEE App versions up to 1.7.12, specifically within the password reset confirmation code handler. It involves improper restriction of excessive authentication attempts, potentially allowing an attacker to bypass authentication. The attack can be launched remotely, but its complexity is high, and exploitation is considered difficult. While a public exploit exists, there is no evidence of active exploitation, and it has garnered minimal community discussion or media coverage. Upgrading to version 1.7.15 resolves this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Tenda | TDSEE App | 1.7.0, 1.7.1, 1.7.10, 1.7.11, 1.7.12, 1.7.2, 1.7.3, 1.7.4, 1.7.5, 1.7.6, 1.7.7, 1.7.8, 1.7.9CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.