VYPR
Critical severity9.8NVD Advisory· Published Dec 7, 2023· Updated Jun 17, 2026

CVE-2023-49429

CVE-2023-49429

Description

Tenda AX9 V22.03.01.46 was discovered to contain a SQL command injection vulnerability in the 'setDeviceInfo' feature through the 'mac' parameter at /goform/setModules.

Affected products

3
  • Tenda/AX9llm-fuzzy2 versions
    V22.03.01.46+ 1 more
    • (no CPE)range: V22.03.01.46
    • (no CPE)
  • cpe:2.3:o:tenda:ax9_firmware:22.03.01.46:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.