CVE-2023-47422

An access control issue in /usr/sbin/httpd in Tenda TX9 V1 V22.03.02.54, Tenda AX3 V3 V16.03.12.11, Tenda AX9 V1 V22.03.01.46, and Tenda AX12 V1 V22.03.01.46 allows attackers to bypass authentication on any endpoint via a crafted URL.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tenda:tx9_firmware:22.03.02.54:*:*:*:*:*:*:*
cpe:2.3:h:tenda:tx9:v1:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:tenda:ax3_firmware:16.03.12.11:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ax3:v3:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:tenda:ax9_firmware:22.03.01.46:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ax9:v1:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:tenda:ax12_firmware:22.03.01.46:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ax12:v1:*:*:*:*:*:*:*

History

25 Apr 2025, 20:26

Type Values Removed Values Added
First Time Tenda ax12
Tenda tx9 Firmware
Tenda ax12 Firmware
Tenda ax3 Firmware
Tenda ax9
Tenda
Tenda tx9
Tenda ax3
Tenda ax9 Firmware
References () https://github.com/xiaobye-ctf/My-CVE/tree/main/Tenda/CVE-2023-47422 - () https://github.com/xiaobye-ctf/My-CVE/tree/main/Tenda/CVE-2023-47422 - Exploit, Third Party Advisory
CPE cpe:2.3:o:tenda:tx9_firmware:22.03.02.54:*:*:*:*:*:*:*
cpe:2.3:o:tenda:ax12_firmware:22.03.01.46:*:*:*:*:*:*:*
cpe:2.3:o:tenda:ax3_firmware:16.03.12.11:*:*:*:*:*:*:*
cpe:2.3:h:tenda:tx9:v1:*:*:*:*:*:*:*
cpe:2.3:o:tenda:ax9_firmware:22.03.01.46:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ax9:v1:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ax12:v1:*:*:*:*:*:*:*
cpe:2.3:h:tenda:ax3:v3:*:*:*:*:*:*:*

21 Nov 2024, 08:30

Type Values Removed Values Added
References () https://github.com/xiaobye-ctf/My-CVE/tree/main/Tenda/CVE-2023-47422 - () https://github.com/xiaobye-ctf/My-CVE/tree/main/Tenda/CVE-2023-47422 -

26 Aug 2024, 16:35

Type Values Removed Values Added
CWE CWE-284
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

22 Feb 2024, 19:07

Type Values Removed Values Added
Summary
  • (es) Un problema de control de acceso en /usr/sbin/httpd en Tenda TX9 V1 V22.03.02.54, Tenda AX3 V3 V16.03.12.11, Tenda AX9 V1 V22.03.01.46 y Tenda AX12 V1 V22.03.01.46 permite a los atacantes para omitir la autenticación en cualquier endpoint a través de una URL manipulada.

20 Feb 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-20 22:15

Updated : 2025-04-25 20:26


NVD link : CVE-2023-47422

Mitre link : CVE-2023-47422

CVE.ORG link : CVE-2023-47422


JSON object : View

Products Affected

tenda

  • ax3_firmware
  • ax12
  • ax9_firmware
  • ax12_firmware
  • tx9_firmware
  • ax9
  • ax3
  • tx9
CWE
CWE-284

Improper Access Control