First published: Thu Dec 07 2023(Updated: )
Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list' parameter at /goform/SetNetControlList.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Tenda AX12 Firmware | =22.03.01.46 | |
Tenda AX12 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-49437 is classified as a high severity vulnerability due to its potential for command injection.
To fix CVE-2023-49437, update the Tenda AX12 firmware to a secure version that addresses the command injection vulnerability.
CVE-2023-49437 specifically affects the Tenda AX12 firmware version 22.03.01.46.
Yes, exploitation of CVE-2023-49437 can allow attackers to execute arbitrary commands, potentially leading to unauthorized access.
Currently, the best workaround for CVE-2023-49437 is to restrict access to the device interface and apply immediate firmware updates.