Tenda
Tenda AX9 Firmware: vulnerabilidades y CVE
Tenda AX9 Firmware tiene 11 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 8 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses1
Críticas8
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-14636 | Baja (2.9) | 0.29% | — | 13 dic 2025 | A security flaw has been discovered in Tenda AX9 22.03.01.46. This affects the function image_check of the component httpd. The manipulation results in use of weak hash. It is possible to launch the attack remotely. A… |
| CVE-2024-39963 | Alta (8) | 1.5% | — | 19 jul 2024 | AX3000 Dual-Band Gigabit Wi-Fi 6 Router AX9 V22.03.01.46 and AX3000 Dual-Band Gigabit Wi-Fi 6 Router AX12 V1.0 V22.03.01.46 were discovered to contain an authenticated remote command execution (RCE) vulnerability via… |
| CVE-2023-47422 | Alta (8.8) | 0.49% | — | 20 feb 2024 | An access control issue in /usr/sbin/httpd in Tenda TX9 V1 V22.03.02.54, Tenda AX3 V3 V16.03.12.11, Tenda AX9 V1 V22.03.01.46, and Tenda AX12 V1 V22.03.01.46 allows attackers to bypass authentication on any endpoint via… |
| CVE-2023-49436 | Crítica (9.8) | 2.4% | — | 7 dic 2023 | Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list' parameter at /goform/SetNetControlList. |
| CVE-2023-49435 | Crítica (9.8) | 2.4% | — | 7 dic 2023 | Tenda AX9 V22.03.01.46 is vulnerable to command injection. |
| CVE-2023-49434 | Crítica (9.8) | 0.92% | — | 7 dic 2023 | Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetNetControlList. |
| CVE-2023-49433 | Crítica (9.8) | 0.92% | — | 7 dic 2023 | Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetVirtualServerCfg. |
| CVE-2023-49432 | Crítica (9.8) | 0.92% | — | 7 dic 2023 | Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'deviceList' parameter at /goform/setMacFilterCfg. |
| CVE-2023-49431 | Crítica (9.8) | 2.4% | — | 7 dic 2023 | Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /goform/SetOnlineDevName. |
| CVE-2023-49430 | Crítica (9.8) | 0.92% | — | 7 dic 2023 | Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetStaticRouteCfg. |
| CVE-2023-49429 | Crítica (9.8) | 2.4% | — | 7 dic 2023 | Tenda AX9 V22.03.01.46 was discovered to contain a SQL command injection vulnerability in the 'setDeviceInfo' feature through the 'mac' parameter at /goform/setModules. |