CVE-2023-49429: Command Injection
Published Dec 7, 2023
·Updated
Tenda AX9 V22.03.01.46 was discovered to contain a SQL command injection vulnerability in the 'setDeviceInfo' feature through the 'mac' parameter at /goform/setModules.
Affected Software
2 affected components
All of the following
Tenda Ax9 Firmware=22.03.01.46
Tenda AX9
Event History
Dec 7, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-49429?
CVE-2023-49429 is classified as a high-severity SQL command injection vulnerability.
2
How do I fix CVE-2023-49429?
To fix CVE-2023-49429, update the Tenda AX9 firmware to a version that addresses the vulnerability.
3
What systems are affected by CVE-2023-49429?
CVE-2023-49429 affects the Tenda AX9 firmware version 22.03.01.46.
4
What is the impact of exploiting CVE-2023-49429?
Exploiting CVE-2023-49429 can lead to unauthorized access to the database and potential leakage of sensitive information.
5
What feature contains the vulnerability in CVE-2023-49429?
The SQL command injection vulnerability in CVE-2023-49429 is found in the 'setDeviceInfo' feature.