SQL Command Injection Vulnerability in Tenda AX9 Routers
CVE-2023-49429
9.8CRITICAL
What is CVE-2023-49429?
The Tenda AX9 router version V22.03.01.46 is susceptible to a SQL command injection vulnerability that affects the 'setDeviceInfo' feature. An attacker can exploit this weakness through the 'mac' parameter at the '/goform/setModules' endpoint, potentially allowing unauthorized access to sensitive data or control of the device's database.