CVE-2023-49406: Critical severity tenda w30e firmware vulnerability
Published Dec 7, 2023
·Updated
Tenda W30E V16.01.0.12(4843) was discovered to contain a Command Execution vulnerability via the function /goform/telnet.
Affected Software
2 affected components
All of the following
Tenda W30e Firmware=16.01.0.12\(4843\)
Tenda W30E
Event History
Dec 7, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-49406?
CVE-2023-49406 is classified as a high severity vulnerability due to its potential to allow command execution on the affected device.
2
How do I fix CVE-2023-49406?
To fix CVE-2023-49406, update the Tenda W30E firmware to a version that addresses this vulnerability.
3
What does CVE-2023-49406 affect?
CVE-2023-49406 affects Tenda W30E devices running firmware version 16.01.0.12(4843).
4
What type of vulnerability is CVE-2023-49406?
CVE-2023-49406 is a command execution vulnerability that can be exploited remotely via the '/goform/telnet' function.
5
Can CVE-2023-49406 be exploited without authentication?
Yes, CVE-2023-49406 can potentially be exploited without authentication, allowing remote attackers to execute commands.