Critical severity9.8NVD Advisory· Published Dec 7, 2023· Updated Jun 17, 2026
CVE-2023-49429
CVE-2023-49429
Description
Tenda AX9 V22.03.01.46 was discovered to contain a SQL command injection vulnerability in the 'setDeviceInfo' feature through the 'mac' parameter at /goform/setModules.
Affected products
2Patches
Vulnerability mechanics
References
1- github.com/ef4tless/vuln/blob/master/iot/AX9/setDeviceInfo.mdnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.