First published: Thu Dec 07 2023(Updated: )
Tenda AX9 V22.03.01.46 was discovered to contain a SQL command injection vulnerability in the 'setDeviceInfo' feature through the 'mac' parameter at /goform/setModules.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Tenda AX9 Firmware | =22.03.01.46 | |
Tenda AX9 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-49429 is classified as a high-severity SQL command injection vulnerability.
To fix CVE-2023-49429, update the Tenda AX9 firmware to a version that addresses the vulnerability.
CVE-2023-49429 affects the Tenda AX9 firmware version 22.03.01.46.
Exploiting CVE-2023-49429 can lead to unauthorized access to the database and potential leakage of sensitive information.
The SQL command injection vulnerability in CVE-2023-49429 is found in the 'setDeviceInfo' feature.