An access control issue in /usr/sbin/httpd in Tenda TX9 V1 V22.03.02.54, Tenda AX3 V3 V16.03.12.11, Tenda AX9 V1 V22.03.01.46, and Tenda AX12 V1 V22.03.01.46 allows attackers to bypass authentication on any endpoint via a crafted URL.
| Software | From | Fixed in |
|---|---|---|
| tenda / tx9_firmware | 22.03.02.54 | 22.03.02.54.x |
| tenda / ax3_firmware | 16.03.12.11 | 16.03.12.11.x |
| tenda / ax9_firmware | 22.03.01.46 | 22.03.01.46.x |
| tenda / ax12_firmware | 22.03.01.46 | 22.03.01.46.x |