Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-47422


An access control issue in /usr/sbin/httpd in Tenda TX9 V1 V22.03.02.54, Tenda AX3 V3 V16.03.12.11, Tenda AX9 V1 V22.03.01.46, and Tenda AX12 V1 V22.03.01.46 allows attackers to bypass authentication on any endpoint via a crafted URL.


Published

2024-02-20T22:15:08.143

Last Modified

2025-04-25T20:26:01.170

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-284

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System tenda tx9_firmware 22.03.02.54 Yes
Hardware tenda tx9 v1 No
Operating System tenda ax3_firmware 16.03.12.11 Yes
Hardware tenda ax3 v3 No
Operating System tenda ax9_firmware 22.03.01.46 Yes
Hardware tenda ax9 v1 No
Operating System tenda ax12_firmware 22.03.01.46 Yes
Hardware tenda ax12 v1 No

References