First published: Thu Dec 07 2023(Updated: )
Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /goform/SetOnlineDevName.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Tenda Ax12 Firmware | =22.03.01.46 | |
Tenda AX12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-49428 is critical.
The affected software version of CVE-2023-49428 is Tenda AX12 Firmware version 22.03.01.46.
CVE-2023-49428 is a command injection vulnerability in the 'mac' parameter at /goform/SetOnlineDevName in Tenda AX12 V22.03.01.46 firmware.
To fix CVE-2023-49428, upgrade to a patched version of Tenda AX12 firmware.
You can find more information about CVE-2023-49428 at the following reference link: [GitHub - CVE-2023-49428](https://github.com/ef4tless/vuln/blob/master/iot/AX12/SetOnlineDevName.md)