Get real-time updates on Telegram
CVE-2025-11666: RP3 Pro 22.5.7.0, 22.5.7.1, 22.5.7.2, 22.5.7.3, 22.5.7.4, 22.5.7.5, 22.5.7.6, 22.5.7.7, 22.5.7.8, 22.5.7.9, 22.5.7.10…
CVE-2025-11666. CVSS 3.1 base score 6.7 (MEDIUM, Vendor/CNA). EPSS 0.00158 (percentile 0.0428), scored 2026-10-06.
Affected technology
RP3 Pro · 22.5.7.0, 22.5.7.1, 22.5.7.2, 22.5.7.3, 22.5.7.4, 22.5.7.5, 22.5.7.6, 22.5.7.7, 22.5.7.8, 22.5.7.9, 22.5.7.10, 22.5.7.11, 22.5.7.12, 22.5.7.13, 22.5.7.14, 22.5.7.15, 22.5.7.16, 22.5.7.17, 22.5.7.18, 22.5.7.19, 22.5.7.20, 22.5.7.21, 22.5.7.22, 22.5.7.23, 22.5.7.24, 22.5.7.25, 22.5.7.26, 22.5.7.27, 22.5.7.28, 22.5.7.29, 22.5.7.30, 22.5.7.31, 22.5.7.32, 22.5.7.33, 22.5.7.34, 22.5.7.35, 22.5.7.36, 22.5.7.37, 22.5.7.38, 22.5.7.39, 22.5.7.40, 22.5.7.41, 22.5.7.42, 22.5.7.43, 22.5.7.44, 22.5.7.45, 22.5.7.46, 22.5.7.47, 22.5.7.48, 22.5.7.49, 22.5.7.50, 22.5.7.51, 22.5.7.52, 22.5.7.53, 22.5.7.54, 22.5.7.55, 22.5.7.56, 22.5.7.57, 22.5.7.58, 22.5.7.59, 22.5.7.60, 22.5.7.61, 22.5.7.62, 22.5.7.63, 22.5.7.64, 22.5.7.65, 22.5.7.66, 22.5.7.67, 22.5.7.68, 22.5.7.69, 22.5.7.70, 22.5.7.71, 22.5.7.72, 22.5.7.73, 22.5.7.74, 22.5.7.75, 22.5.7.76, 22.5.7.77, 22.5.7.78, 22.5.7.79, 22.5.7.80, 22.5.7.81, 22.5.7.82, 22.5.7.83, 22.5.7.84, 22.5.7.85, 22.5.7.86, 22.5.7.87, 22.5.7.88, 22.5.7.89, 22.5.7.90, 22.5.7.91, 22.5.7.92, 22.5.7.93
Tenda
Description’s affected range: up to 22.5.7.93
Component: Firmware Update Handler
Function: of
File: force_upgrade.sh
Attack conditions (VulDB, CVSS 4.0): Local · High privileges required · No user interaction required
What an attacker can do
VulDB’s CVSS 4.0 assessment (base score 7.0/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
- CWE
- CWE-255, CWE-259
- CCR priority
- 26.8 /100 (P4)
- CVSS 3.1
- 6.7 /10 · CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H · Vendor/CNA
- EPSS
- 0.00158 · percentile 0.04309 · 2026-10-08
- KEV
- no
Provenance
- FIRST EPSS daily exploit-probability · Source record · observed 2026-10-08 17:36:22.845483+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-08 17:32:11.049884+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2025-11666.html