CVE-2023-51100: Command Injection
Published Dec 26, 2023
·Updated
Tenda W9 V1.0.0.7(4456)CN was discovered to contain a command injection vulnerability via the function formGetDiagnoseInfo .
Affected Software
2 affected components
All of the following
Tenda W9 Firmware=1.0.0.7\(4456\)_cn
Tenda W9
Event History
Dec 26, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-51100?
CVE-2023-51100 has been classified as a high severity command injection vulnerability that can allow an attacker to execute arbitrary commands.
2
How do I fix CVE-2023-51100?
To mitigate CVE-2023-51100, update the Tenda W9 firmware to the latest version that addresses this vulnerability.
3
What is the impact of CVE-2023-51100?
The impact of CVE-2023-51100 includes unauthorized command execution, which can compromise the device's functionality and security.
4
Which devices are affected by CVE-2023-51100?
CVE-2023-51100 specifically affects the Tenda W9 firmware version 1.0.0.7(4456)_CN.
5
How was CVE-2023-51100 discovered?
CVE-2023-51100 was discovered through security assessments that identified a command injection vulnerability in the formGetDiagnoseInfo function.