CVE-2023-49428: Command Injection
Published Dec 7, 2023
·Updated
Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /goform/SetOnlineDevName.
Affected Software
2 affected components
All of the following
Tenda Ax12 Firmware=22.03.01.46
Tenda AX12
Event History
Dec 7, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-49428?
The severity of CVE-2023-49428 is critical.
2
What is the affected software version of CVE-2023-49428?
The affected software version of CVE-2023-49428 is Tenda AX12 Firmware version 22.03.01.46.
3
What is the vulnerability description of CVE-2023-49428?
CVE-2023-49428 is a command injection vulnerability in the 'mac' parameter at /goform/SetOnlineDevName in Tenda AX12 V22.03.01.46 firmware.
4
How can I fix CVE-2023-49428?
To fix CVE-2023-49428, upgrade to a patched version of Tenda AX12 firmware.
5
Where can I find more information about CVE-2023-49428?
You can find more information about CVE-2023-49428 at the following reference link: [GitHub - CVE-2023-49428](https://github.com/ef4tless/vuln/blob/master/iot/AX12/SetOnlineDevName.md)