A vulnerability was found in Tenda AC9 15.03.05.19. It has been rated as problematic. The impacted element is an unknown function of the file /etc_ro/shadow of the component Administrative Interface. This manipulation causes hard-coded credentials.

This vulnerability is handled as CVE-2025-9731. It is possible to launch the attack on the local host. Additionally, an exploit exists.