Search Results (11 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-14636 1 Tenda 2 Ax9, Ax9 Firmware 2026-02-24 3.7 Low
A security flaw has been discovered in Tenda AX9 22.03.01.46. This affects the function image_check of the component httpd. The manipulation results in use of weak hash. It is possible to launch the attack remotely. A high complexity level is associated with this attack. It is indicated that the exploitability is difficult. The exploit has been released to the public and may be used for attacks.
CVE-2024-39963 1 Tenda 4 Ax12, Ax12 Firmware, Ax9 and 1 more 2025-06-04 8 High
AX3000 Dual-Band Gigabit Wi-Fi 6 Router AX9 V22.03.01.46 and AX3000 Dual-Band Gigabit Wi-Fi 6 Router AX12 V1.0 V22.03.01.46 were discovered to contain an authenticated remote command execution (RCE) vulnerability via the macFilterType parameter at /goform/setMacFilterCfg.
CVE-2023-47422 1 Tenda 8 Ax12, Ax12 Firmware, Ax3 and 5 more 2025-04-25 8.8 High
An access control issue in /usr/sbin/httpd in Tenda TX9 V1 V22.03.02.54, Tenda AX3 V3 V16.03.12.11, Tenda AX9 V1 V22.03.01.46, and Tenda AX12 V1 V22.03.01.46 allows attackers to bypass authentication on any endpoint via a crafted URL.
CVE-2023-49432 1 Tenda 2 Ax9, Ax9 Firmware 2024-11-26 9.8 Critical
Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'deviceList' parameter at /goform/setMacFilterCfg.
CVE-2023-49436 1 Tenda 2 Ax9, Ax9 Firmware 2024-11-21 9.8 Critical
Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list' parameter at /goform/SetNetControlList.
CVE-2023-49435 1 Tenda 2 Ax9, Ax9 Firmware 2024-11-21 9.8 Critical
Tenda AX9 V22.03.01.46 is vulnerable to command injection.
CVE-2023-49434 1 Tenda 2 Ax9, Ax9 Firmware 2024-11-21 9.8 Critical
Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetNetControlList.
CVE-2023-49433 1 Tenda 2 Ax9, Ax9 Firmware 2024-11-21 9.8 Critical
Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetVirtualServerCfg.
CVE-2023-49431 1 Tenda 2 Ax9, Ax9 Firmware 2024-11-21 9.8 Critical
Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /goform/SetOnlineDevName.
CVE-2023-49430 1 Tenda 2 Ax9, Ax9 Firmware 2024-11-21 9.8 Critical
Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetStaticRouteCfg.
CVE-2023-49429 1 Tenda 2 Ax9, Ax9 Firmware 2024-11-21 9.8 Critical
Tenda AX9 V22.03.01.46 was discovered to contain a SQL command injection vulnerability in the 'setDeviceInfo' feature through the 'mac' parameter at /goform/setModules.