AX3000 Dual-Band Gigabit Wi-Fi 6 Router AX9 V22.03.01.46 and AX3000 Dual-Band Gigabit Wi-Fi 6 Router AX12 V1.0 V22.03.01.46 were discovered to contain an authenticated remote command execution (RCE) vulnerability via the macFilterType parameter at /goform/setMacFilterCfg.
| Software | From | Fixed in |
|---|---|---|
| tenda / ax9_firmware | 22.03.01.46 | 22.03.01.46.x |
| tenda / ax12_firmware | 22.03.01.46 | 22.03.01.46.x |