First published: Wed Mar 15 2023(Updated: )
Tenda AX3 V16.03.12.11 was discovered to contain a command injection vulnerability via the lanip parameter at /goform/AdvSetLanip.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tenda Ax3 Firmware | =16.03.12.11 | |
Tenda AX3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-27240 is a command injection vulnerability in Tenda AX3 V16.03.12.11, specifically in the lanip parameter at /goform/AdvSetLanip.
CVE-2023-27240 has a severity rating of critical with a score of 9.8.
CVE-2023-27240 allows for command injection via the lanip parameter, potentially leading to remote code execution.
Yes, Tenda AX3 V16.03.12.11 is the only known affected version of the firmware.
Currently, there is no official patch or mitigation available. It is recommended to update to a non-vulnerable version or consider alternative security measures.