First published: Thu Dec 07 2023(Updated: )
Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list' parameter at /goform/SetNetControlList.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Tenda AX9 Firmware | =22.03.01.46 | |
Tenda AX9 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-49436 has a high severity rating due to the command injection vulnerability that can be exploited remotely.
To fix CVE-2023-49436, update your Tenda AX9 firmware to the latest version that addresses this vulnerability.
CVE-2023-49436 exploits a command injection vulnerability found in the 'list' parameter at /goform/SetNetControlList.
CVE-2023-49436 affects users running Tenda AX9 firmware version 22.03.01.46.
Exploitation of CVE-2023-49436 may allow an attacker to execute arbitrary commands on the affected device.