VYPR
Critical severity9.8NVD Advisory· Published Dec 7, 2023· Updated Jun 17, 2026

CVE-2023-49429

CVE-2023-49429

Description

Tenda AX9 V22.03.01.46 was discovered to contain a SQL command injection vulnerability in the 'setDeviceInfo' feature through the 'mac' parameter at /goform/setModules.

Affected products

2
  • Tenda/AX9cpe-rescue2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: V22.03.01.46

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.