CVE-2023-47422
8.8
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)
Description
An access control issue in /usr/sbin/httpd in Tenda TX9 V1 V22.03.02.54, Tenda AX3 V3 V16.03.12.11, Tenda AX9 V1 V22.03.01.46, and Tenda AX12 V1 V22.03.01.46 allows attackers to bypass authentication on any endpoint via a crafted URL.
Affected (4)
Products: Tenda: Tx9 Firmware, Ax3 Firmware, Ax9 Firmware, Ax12 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 22.03.02.54 |
| Running on/with | Platform Versions |
|---|---|
Tenda Tx9 | Version v1 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 16.03.12.11 |
| Running on/with | Platform Versions |
|---|---|
Tenda Ax3 | Version v3 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 22.03.01.46 |
| Running on/with | Platform Versions |
|---|---|
Tenda Ax9 | Version v1 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 22.03.01.46 |
| Running on/with | Platform Versions |
|---|---|
Tenda Ax12 | Version v1 |
References (2)
Source: cve@mitre.org
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Timeline
No history available yet.