Ax9 firmware
This hub aggregates every CVE we track for Ax9 firmware, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.
11
CVEs tracked
8
Critical
2
High
0
In CISA KEV
Severity distribution
CRITICAL8HIGH2LOW1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 11 most recently published vulnerabilities affecting Ax9 firmware.
- CVE-2025-14636Tenda AX9 httpd image_check weak hash3.7
- CVE-2024-39963AX3000 Dual-Band Gigabit Wi-Fi 6 Router AX9 V22.03.01.46 and AX3000 Dual-Band Gigabit Wi-Fi 6 Router AX12 V1.0 V22.03.01.46 were discovered to contain an authenticated remote command execution (RCE...8.0
- CVE-2023-47422An access control issue in /usr/sbin/httpd in Tenda TX9 V1 V22.03.02.54, Tenda AX3 V3 V16.03.12.11, Tenda AX9 V1 V22.03.01.46, and Tenda AX12 V1 V22.03.01.46 allows attackers to bypass authenticati...8.8
- CVE-2023-49431Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /goform/SetOnlineDevName.9.8
- CVE-2023-49432Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'deviceList' parameter at /goform/setMacFilterCfg.9.8
- CVE-2023-49429Tenda AX9 V22.03.01.46 was discovered to contain a SQL command injection vulnerability in the 'setDeviceInfo' feature through the 'mac' parameter at /goform/setModules.9.8
- CVE-2023-49434Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetNetControlList.9.8
- CVE-2023-49435Tenda AX9 V22.03.01.46 is vulnerable to command injection.9.8
- CVE-2023-49430Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetStaticRouteCfg.9.8
- CVE-2023-49433Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetVirtualServerCfg.9.8
- CVE-2023-49436Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list' parameter at /goform/SetNetControlList.9.8
Product normalization is registry-driven with AI assist and human review. How it works