Tenda Ax9 Firmware vulnerabilities

11 known vulnerabilities affecting tenda/ax9_firmware.

Total CVEs
11
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH2MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2025-14636MEDIUMCVSS 6.3v22.03.01.462025-12-13
CVE-2025-14636 [MEDIUM] CWE-327 CVE-2025-14636: A security flaw has been discovered in Tenda AX9 22.03.01.46. This affects the function image_check A security flaw has been discovered in Tenda AX9 22.03.01.46. This affects the function image_check of the component httpd. The manipulation results in use of weak hash. It is possible to launch the attack remotely. A high complexity level is associated with this attack. It is indicated that the exploitability is difficult. The exploit has been relea
nvd
CVE-2024-39963HIGHCVSS 8.0v22.03.01.462024-07-19
CVE-2024-39963 [HIGH] CWE-77 CVE-2024-39963: AX3000 Dual-Band Gigabit Wi-Fi 6 Router AX9 V22.03.01.46 and AX3000 Dual-Band Gigabit Wi-Fi 6 Router AX3000 Dual-Band Gigabit Wi-Fi 6 Router AX9 V22.03.01.46 and AX3000 Dual-Band Gigabit Wi-Fi 6 Router AX12 V1.0 V22.03.01.46 were discovered to contain an authenticated remote command execution (RCE) vulnerability via the macFilterType parameter at /goform/setMacFilterCfg.
nvd
CVE-2023-47422HIGHCVSS 8.8v22.03.01.462024-02-20
CVE-2023-47422 [HIGH] CWE-284 CVE-2023-47422: An access control issue in /usr/sbin/httpd in Tenda TX9 V1 V22.03.02.54, Tenda AX3 V3 V16.03.12.11, An access control issue in /usr/sbin/httpd in Tenda TX9 V1 V22.03.02.54, Tenda AX3 V3 V16.03.12.11, Tenda AX9 V1 V22.03.01.46, and Tenda AX12 V1 V22.03.01.46 allows attackers to bypass authentication on any endpoint via a crafted URL.
nvd
CVE-2023-49430CRITICALCVSS 9.8v22.03.01.462023-12-07
CVE-2023-49430 [CRITICAL] CWE-787 CVE-2023-49430: Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parame Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetStaticRouteCfg.
nvd
CVE-2023-49431CRITICALCVSS 9.8v22.03.01.462023-12-07
CVE-2023-49431 [CRITICAL] CWE-77 CVE-2023-49431: Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /goform/SetOnlineDevName.
nvd
CVE-2023-49434CRITICALCVSS 9.8v22.03.01.462023-12-07
CVE-2023-49434 [CRITICAL] CWE-787 CVE-2023-49434: Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parame Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetNetControlList.
nvd
CVE-2023-49433CRITICALCVSS 9.8v22.03.01.462023-12-07
CVE-2023-49433 [CRITICAL] CWE-787 CVE-2023-49433: Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parame Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetVirtualServerCfg.
nvd
CVE-2023-49435CRITICALCVSS 9.8v22.03.01.462023-12-07
CVE-2023-49435 [CRITICAL] CWE-77 CVE-2023-49435: Tenda AX9 V22.03.01.46 is vulnerable to command injection. Tenda AX9 V22.03.01.46 is vulnerable to command injection.
nvd
CVE-2023-49429CRITICALCVSS 9.8v22.03.01.462023-12-07
CVE-2023-49429 [CRITICAL] CWE-89 CVE-2023-49429: Tenda AX9 V22.03.01.46 was discovered to contain a SQL command injection vulnerability in the 'setDe Tenda AX9 V22.03.01.46 was discovered to contain a SQL command injection vulnerability in the 'setDeviceInfo' feature through the 'mac' parameter at /goform/setModules.
nvd
CVE-2023-49432CRITICALCVSS 9.8v22.03.01.462023-12-07
CVE-2023-49432 [CRITICAL] CWE-787 CVE-2023-49432: Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'deviceList' Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'deviceList' parameter at /goform/setMacFilterCfg.
nvd
CVE-2023-49436CRITICALCVSS 9.8v22.03.01.462023-12-07
CVE-2023-49436 [CRITICAL] CWE-77 CVE-2023-49436: Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list' parameter at /goform/SetNetControlList.
nvd