Arbitrary Device Locking in Tenda RX9 Pro Firmware
CVE-2023-43885
8.1HIGH
What is CVE-2023-43885?
The Tenda RX9 Pro Firmware V22.03.02.20 contains a vulnerability in its HTTP server component that lacks adequate error handling mechanisms. This deficiency allows authenticated attackers to exploit the system and arbitrarily lock the device, thus disrupting its functionality and access for legitimate users. This issue underscores the importance of robust error management protocols in firmware development to protect against unauthorized control over network devices.