CVE-2023-47422: High severity Tenda TX9 vulnerability
Published Feb 20, 2024
·Updated
An access control issue in /usr/sbin/httpd in Tenda TX9 V1 V22.03.02.54, Tenda AX3 V3 V16.03.12.11, Tenda AX9 V1 V22.03.01.46, and Tenda AX12 V1 V22.03.01.46 allows attackers to bypass authentication on any endpoint via a crafted URL.
Affected Software
12 affected components
Tenda TX9
Tenda AX3
Tenda AX9
Tenda AX12
All of the following
Tenda Tx9 Firmware=22.03.02.54
Tenda TX9=v1
All of the following
Tenda AX3 firmware=16.03.12.11
Tenda AX3=v3
All of the following
Tenda Ax9 Firmware=22.03.01.46
Tenda AX9=v1
All of the following
Tenda Ax12 Firmware=22.03.01.46
Tenda AX12=v1
Event History
Feb 20, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-47422?
CVE-2023-47422 is classified as a critical severity vulnerability due to the potential for unauthorized access.
2
How do I fix CVE-2023-47422?
To fix CVE-2023-47422, update your Tenda device firmware to the latest version provided by the manufacturer.
3
What impact does CVE-2023-47422 have on Tenda devices?
CVE-2023-47422 allows attackers to bypass authentication, leading to unauthorized access to sensitive endpoints.
4
Which Tenda products are affected by CVE-2023-47422?
CVE-2023-47422 affects Tenda TX9, AX3, AX9, and AX12 models with specific firmware versions.
5
Can CVE-2023-47422 be exploited remotely?
Yes, CVE-2023-47422 can be exploited remotely via crafted URLs without authentication.