CVE-2023-27240: Command Injection
Published Mar 15, 2023
·Updated
Tenda AX3 V16.03.12.11 was discovered to contain a command injection vulnerability via the lanip parameter at /goform/AdvSetLanip.
Affected Software
2 affected components
Tenda AX3 firmware=16.03.12.11
Tenda AX3
Event History
Mar 15, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability identified as CVE-2023-27240?
CVE-2023-27240 is a command injection vulnerability in Tenda AX3 V16.03.12.11, specifically in the lanip parameter at /goform/AdvSetLanip.
2
What is the severity of CVE-2023-27240?
CVE-2023-27240 has a severity rating of critical with a score of 9.8.
3
How does CVE-2023-27240 affect Tenda AX3 V16.03.12.11?
CVE-2023-27240 allows for command injection via the lanip parameter, potentially leading to remote code execution.
4
Is Tenda AX3 V16.03.12.11 the only affected version?
Yes, Tenda AX3 V16.03.12.11 is the only known affected version of the firmware.
5
How can I mitigate CVE-2023-27240 in Tenda AX3 V16.03.12.11?
Currently, there is no official patch or mitigation available. It is recommended to update to a non-vulnerable version or consider alternative security measures.