Command Injection Vulnerability in Tenda AX3 Router
CVE-2023-27240
9.8CRITICAL
What is CVE-2023-27240?
A command injection vulnerability has been identified in the Tenda AX3 router, specifically affecting the version V16.03.12.11. This flaw arises from improper handling of the 'lanip' parameter at the '/goform/AdvSetLanip' endpoint, allowing unauthorized execution of arbitrary commands. Exploitation of this vulnerability can lead to significant security breaches, including unauthorized access and manipulation of network settings.