CVE-2023-49424: Critical severity tenda ax12 firmware vulnerability
Published Dec 7, 2023
·Updated
Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the list parameter at /goform/SetVirtualServerCfg.
Affected Software
2 affected components
All of the following
Tenda Ax12 Firmware=22.03.01.46
Tenda AX12
Event History
Dec 7, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-49424?
The severity of CVE-2023-49424 is critical with a CVSS score of 9.8.
2
How does CVE-2023-49424 affect Tenda AX12 firmware version 22.03.01.46?
CVE-2023-49424 affects Tenda AX12 firmware version 22.03.01.46 by triggering a stack overflow via the 'list' parameter at /goform/SetVirtualServerCfg.
3
Is Tenda AX12 firmware version 22.03.01.46 vulnerable to CVE-2023-49424?
Yes, Tenda AX12 firmware version 22.03.01.46 is vulnerable to CVE-2023-49424.
4
How can I fix the vulnerability CVE-2023-49424?
To fix the vulnerability CVE-2023-49424, it is recommended to update the firmware of Tenda AX12 to a patched version provided by the vendor.
5
Where can I find more information about CVE-2023-49424?
More information about CVE-2023-49424 can be found at the following reference: https://github.com/ef4tless/vuln/blob/master/iot/AX12/SetVirtualServerCfg.md