CVE-2023-49040: Command Injection
Published Nov 27, 2023
·Updated
An issue in Tneda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the adslPwd parameter in the formfastsettinginternetset function.
Affected Software
2 affected components
All of the following
Tenda Ax1803 Firmware=1.0.0.1
Tenda ax1803
Event History
Nov 27, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2023-49040.
2
What is the severity of CVE-2023-49040?
The severity of CVE-2023-49040 is critical with a CVSS score of 9.8.
3
Which software is affected by this vulnerability?
Tenda AX1803 firmware version 1.0.0.1 is affected by this vulnerability.
4
How can a remote attacker exploit this vulnerability?
A remote attacker can exploit this vulnerability by executing arbitrary code via the adslPwd parameter in the form_fast_setting_internet_set function.
5
Is Tenda AX1803 hardware affected by this vulnerability?
No, Tenda AX1803 hardware is not affected by this vulnerability.