An access control issue in /usr/sbin/httpd in Tenda TX9 V1 V22.03.02.54, Tenda AX3 V3 V16.03.12.11, Tenda AX9 V1 V22.03.01.46, and Tenda AX12 V1 V22.03.01.46 allows attackers to bypass authentication on any endpoint via a crafted URL.
2024-02-20T22:15:08.143
2025-04-25T20:26:01.170
Analyzed
CVSSv3.1: 8.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | tenda | tx9_firmware | 22.03.02.54 | Yes |
Hardware | tenda | tx9 | v1 | No |
Operating System | tenda | ax3_firmware | 16.03.12.11 | Yes |
Hardware | tenda | ax3 | v3 | No |
Operating System | tenda | ax9_firmware | 22.03.01.46 | Yes |
Hardware | tenda | ax9 | v1 | No |
Operating System | tenda | ax12_firmware | 22.03.01.46 | Yes |
Hardware | tenda | ax12 | v1 | No |