MEDIUM 4.6

CVE-2026-38571: Tenda N300 F3 Unauthenticated UART Debug Console & Cleartext WPA2 Credentials

The Tenda N300 F3 router (V603 firmware) stores Wi-Fi security passwords in plain text and allows anyone with physical access to the device's serial port to read them without any authentication. The same serial console also permits attackers to read or write data directly to the device's memory, potentially compromising the router's operation or extracting additional sensitive information. This is a physically proximate attack—the attacker must be able to connect a cable to the device—but requires no special knowledge or authentication once connected.

Source data · NVD / CISA · public domain

CVSS
3.1 · 4.6 MEDIUM · CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weaknesses (CWE)
CWE-312
Affected products
0 configuration(s)
Published / Modified
2026-06-26 / 2026-06-29

NVD description (verbatim)

Cleartext storage and exposure of WPA2 credentials, and missing authentication on the rr/wr memory read/write commands, in the unauthenticated UART debug console of the Tenda N300 F3 (V603) allow a physically proximate attacker to obtain stored WPA2 credentials in cleartext and to read or write arbitrary memory via the serial console.

2 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

CVE-2026-38571 affects the Tenda N300 F3 V603 firmware and involves two related security failures in the UART debug console. First, WPA2 pre-shared keys are stored in plaintext and are accessible via the serial port without authentication. Second, the unauthenticated debug interface exposes memory read/write (rr/wr) commands, allowing an attacker to directly manipulate device memory. The UART port is typically available on the PCB via test pads or connectors, making it accessible to an attacker with brief physical access. This maps to CWE-312 (Cleartext Storage of Sensitive Information), a foundational weakness in credential handling.

Business impact

For organizations deploying Tenda N300 F3 routers, this vulnerability creates a secondary-layer risk. While physical access is required, compromised WPA2 credentials enable unauthorized wireless network access, potentially exposing internal traffic or guest networks. Memory manipulation could degrade router availability or be used as a pivot point if the device sits on a trusted network segment. The practical impact depends on deployment context: a home user faces greater risk than an enterprise with network segmentation and centralized access control, but offices with open areas or shared spaces should assess their physical security posture.

Affected systems

The Tenda N300 F3 router with V603 firmware is explicitly affected. Organizations using this model in branch offices, retail locations, small offices, or environments with inadequate physical security should prioritize assessment. This is a single model/firmware version; other Tenda router models and firmware versions may have similar issues but are not confirmed to be affected by this CVE. Verify your deployed firmware version against vendor documentation to confirm exposure.

Exploitability

Exploitability requires physical access to the UART debug console on the router's circuit board. This is a non-trivial barrier in most enterprise settings but may be realistic in environments with poor physical security, unlocked network closets, or shared office spaces. Once access is gained, exploitation is straightforward—no additional tools beyond a USB serial adapter (widely available, inexpensive) and terminal software are needed. Authentication is not required, and the attack leaves minimal forensic evidence. The CVSS score of 4.6 (Medium) reflects the high confidentiality impact (access to WPA2 keys) balanced against the physical access requirement.

Remediation

Immediate mitigation includes restricting physical access to networking equipment via locked cabinets or rooms, and disabling or physically disconnecting UART pins if the debug interface cannot be disabled in firmware. Check Tenda's advisory and security updates for V603 or later firmware versions that disable the unauthenticated debug console or encrypt stored credentials. If available, upgrade to a patched firmware version. For high-risk deployments, consider replacing the device with a model from a vendor with better security practices around debug interfaces and credential storage.

Patch guidance

Monitor Tenda's official security advisories for firmware updates to the N300 F3 that address unauthenticated UART access and cleartext credential storage. Firmware patches should implement authentication on the debug console and encrypt WPA2 credentials at rest. Verify patch availability and version numbers directly from Tenda's support portal before deploying to production. If no official patch is available within a reasonable timeframe, escalate the replacement timeline based on your organization's risk tolerance and the physical security controls already in place.

Detection guidance

Detect unauthorized access to the device by monitoring UART connections (if logging is available), reviewing physical access logs for network closets, and conducting physical audits of router cabling and port coverage. Wireless network monitoring can detect unauthorized clients using captured WPA2 credentials, though this occurs after the compromise. Threat hunters should identify all Tenda N300 F3 V603 devices in inventory and assess their physical environment. Monitor for unexpected memory corruption or router reboots that may indicate memory manipulation attempts.

Why prioritize this

Although rated CVSS 4.6 (Medium), this vulnerability warrants focused attention in organizations where physical security controls are weak or where routers handle sensitive network traffic. The impact on credential confidentiality is severe, and the barrier to exploitation (physical access) is context-dependent. Prioritization should account for facility layout, access controls, and whether the router protects critical data or guest networks. Organizations with strong physical security and network segmentation can safely defer remediation; those with open access to network equipment should treat this as high priority.

Risk score, explained

The CVSS 3.1 score of 4.6 reflects a High confidentiality impact (CWE-312 cleartext storage) and a No integrity/availability impact from the credentials themselves—but the memory write capability introduces potential for availability or system integrity harm. The Physical attack vector (AV:P) and Low complexity (AC:L) are balanced by the requirement for physical proximity, which is a real-world barrier. The absence of required privileges (PR:N) and user interaction (UI:N) increases the severity of the attack conditional on physical access. This is a realistic Medium-severity finding for security programs: not immediately catastrophic, but warranting remediation and included in patch management cycles.

Frequently asked questions

Do I need to worry about this if my Tenda routers are in a locked network closet?

Physical access is a hard requirement for this attack, so if your network closets are restricted to authorized personnel and regularly audited, your risk is materially lower. However, you should still patch or replace the device when feasible, and ensure that authorized staff (maintenance contractors, IT support) cannot inadvertently expose the UART pins.

Can I test for this vulnerability myself?

Only if you own the device and have the skills to safely connect a USB serial adapter to the UART pads. We do not provide exploit code or step-by-step instructions. If you suspect exposure, verify your Tenda firmware version against the CVE and contact Tenda support for patched firmware or replacement guidance.

What if Tenda has not released a patch yet?

Check Tenda's official security advisories regularly. In the interim, enforce physical security controls (locked enclosures, access logging), rotate your WPA2 credentials frequently, and consider replacing the device with a router from a vendor with better security practices around debug interfaces. Disabling or physically removing the UART interface is a last-resort mitigating control.

Does this affect other Tenda router models?

This CVE is specific to the N300 F3 V603 firmware. Other Tenda models and firmware versions may have similar issues, but they are not confirmed to be affected by this CVE. Check Tenda's advisory to see if related models are mentioned, and assess your full Tenda inventory independently.

This analysis is provided for informational purposes and does not constitute legal or technical advice. The information is current as of the publication date and may change as vendors release patches or provide additional guidance. Organizations should verify all technical details, patch availability, and affected product versions directly from Tenda and through their own testing. Physical access to network equipment should be restricted regardless of individual CVE status. SEC.co makes no warranty regarding the completeness or accuracy of this analysis and recommends independent verification before making deployment or remediation decisions. Source: NVD (public-domain), retrieved 2026-08-05. Analysis generated by SEC.co (claude-haiku-4-5).