First published: Tue Oct 24 2023(Updated: )
Tenda W18E V16.01.0.8(1576) has a command injection vulnerability via the hostName parameter in the formSetNetCheckTools function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Tenda W18e Firmware | =16.01.0.8\(1576\) | |
Tenda W18e Firmware | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-46370 is a command injection vulnerability in Tenda W18E V16.01.0.8(1576) router firmware.
CVE-2023-46370 has a severity score of 9.8 out of 10, making it a critical vulnerability.
CVE-2023-46370 occurs due to a command injection vulnerability in the hostName parameter of the formSetNetCheckTools function in Tenda W18E firmware.
Yes, Tenda W18E V16.01.0.8(1576) is affected by CVE-2023-46370.
To mitigate the CVE-2023-46370 vulnerability, update your Tenda W18E router firmware to a version that has the fix.