CVE-2023-47422 describes an access control bypass vulnerability in the /usr/sbin/httpd component of several Tenda router models, including the TX9 V1, AX3 V3, AX9 V1, and AX12 V1. This flaw allows unauthenticated attackers to bypass authentication on any endpoint by crafting a specific URL. With a CVSS score of 8.8 (HIGH), this vulnerability is easily exploitable over the network with low complexity, potentially leading to high impact on confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
22.03.02.54CPE matchmatch criteria | cpe:2.3:o:tenda:tx9_firmware:22.03.02.54:*:*:*:*:*:*:* | ||
16.03.12.11CPE matchmatch criteria | cpe:2.3:o:tenda:ax3_firmware:16.03.12.11:*:*:*:*:*:*:* | ||
22.03.01.46CPE matchmatch criteria | cpe:2.3:o:tenda:ax9_firmware:22.03.01.46:*:*:*:*:*:*:* | ||
22.03.01.46CPE matchmatch criteria | cpe:2.3:o:tenda:ax12_firmware:22.03.01.46:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.