CVE-2023-49431: Command Injection
Published Dec 7, 2023
·Updated
Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /goform/SetOnlineDevName.
Affected Software
2 affected components
All of the following
Tenda Ax9 Firmware=22.03.01.46
Tenda AX9
Event History
Dec 7, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-49431?
CVE-2023-49431 is classified as a high-severity command injection vulnerability.
2
How do I fix CVE-2023-49431?
To fix CVE-2023-49431, upgrade Tenda AX9 firmware to version 22.03.01.47 or later.
3
What is the vulnerable component in CVE-2023-49431?
The vulnerable component in CVE-2023-49431 is the 'mac' parameter at /goform/SetOnlineDevName.
4
Who is affected by CVE-2023-49431?
Users of Tenda AX9 devices running firmware version 22.03.01.46 are affected by CVE-2023-49431.
5
Can CVE-2023-49431 be exploited remotely?
Yes, CVE-2023-49431 can be exploited remotely if an attacker has access to the network.