First published: Tue Dec 26 2023(Updated: )
Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a command injection vulnerability via the function formexeCommand .
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Tenda W9 Router | =1.0.0.7\(4456\)_cn | |
Tenda W9 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-51099 has a high severity rating due to the potential for command injection attacks.
CVE-2023-51099 allows attackers to execute arbitrary commands on Tenda W9 devices running the specified firmware.
To mitigate CVE-2023-51099, it is recommended to update the Tenda W9 firmware to the latest version provided by the manufacturer.
Any user operating Tenda W9 firmware version 1.0.0.7(4456)_CN is vulnerable to CVE-2023-51099.
CVE-2023-51099 is caused by improper input validation in the formexeCommand function of the firmware.