CVE-2023-49437: Command Injection
Published Dec 7, 2023
·Updated
Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list' parameter at /goform/SetNetControlList.
Affected Software
2 affected components
All of the following
Tenda Ax12 Firmware=22.03.01.46
Tenda AX12
Event History
Dec 7, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-49437?
CVE-2023-49437 is classified as a high severity vulnerability due to its potential for command injection.
2
How do I fix CVE-2023-49437?
To fix CVE-2023-49437, update the Tenda AX12 firmware to a secure version that addresses the command injection vulnerability.
3
What products are affected by CVE-2023-49437?
CVE-2023-49437 specifically affects the Tenda AX12 firmware version 22.03.01.46.
4
Can CVE-2023-49437 lead to unauthorized access?
Yes, exploitation of CVE-2023-49437 can allow attackers to execute arbitrary commands, potentially leading to unauthorized access.
5
Is there a workaround for CVE-2023-49437?
Currently, the best workaround for CVE-2023-49437 is to restrict access to the device interface and apply immediate firmware updates.