Vulnerabilities
Vulnerable Software
Tenda:  >> Ax9 Firmware  Security Vulnerabilities
An access control issue in /usr/sbin/httpd in Tenda TX9 V1 V22.03.02.54, Tenda AX3 V3 V16.03.12.11, Tenda AX9 V1 V22.03.01.46, and Tenda AX12 V1 V22.03.01.46 allows attackers to bypass authentication on any endpoint via a crafted URL.
CVSS Score
8.8
EPSS Score
0.0
Published
2024-02-20
Tenda AX9 V22.03.01.46 was discovered to contain a SQL command injection vulnerability in the 'setDeviceInfo' feature through the 'mac' parameter at /goform/setModules.
CVSS Score
9.8
EPSS Score
0.019
Published
2023-12-07
Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetStaticRouteCfg.
CVSS Score
9.8
EPSS Score
0.001
Published
2023-12-07
Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /goform/SetOnlineDevName.
CVSS Score
9.8
EPSS Score
0.02
Published
2023-12-07
Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'deviceList' parameter at /goform/setMacFilterCfg.
CVSS Score
9.8
EPSS Score
0.001
Published
2023-12-07
Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetVirtualServerCfg.
CVSS Score
9.8
EPSS Score
0.003
Published
2023-12-07
Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetNetControlList.
CVSS Score
9.8
EPSS Score
0.003
Published
2023-12-07
Tenda AX9 V22.03.01.46 is vulnerable to command injection.
CVSS Score
9.8
EPSS Score
0.044
Published
2023-12-07
Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list' parameter at /goform/SetNetControlList.
CVSS Score
9.8
EPSS Score
0.044
Published
2023-12-07


Contact Us

Shodan ® - All rights reserved