CVE-2023-51099: Command Injection
Published Dec 26, 2023
·Updated
Tenda W9 V1.0.0.7(4456)CN was discovered to contain a command injection vulnerability via the function formexeCommand .
Affected Software
2 affected components
All of the following
Tenda W9 Firmware=1.0.0.7\(4456\)_cn
Tenda W9
Event History
Dec 26, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-51099?
CVE-2023-51099 has a high severity rating due to the potential for command injection attacks.
2
How does CVE-2023-51099 affect Tenda W9 devices?
CVE-2023-51099 allows attackers to execute arbitrary commands on Tenda W9 devices running the specified firmware.
3
How do I fix CVE-2023-51099?
To mitigate CVE-2023-51099, it is recommended to update the Tenda W9 firmware to the latest version provided by the manufacturer.
4
Who is affected by CVE-2023-51099?
Any user operating Tenda W9 firmware version 1.0.0.7(4456)_CN is vulnerable to CVE-2023-51099.
5
What is the cause of CVE-2023-51099?
CVE-2023-51099 is caused by improper input validation in the formexeCommand function of the firmware.