Tenda AX3 v16.03.12.10_CN was discovered to contain a command injection vulnerability in the function WanParameterSetting. This vulnerability allows attackers to execute arbitrary commands via the gateway, dns1, and dns2 parameters.
No PoCs from references.
- https://github.com/ARPSyndicate/cvemon
- https://github.com/pjqwudi/my_vuln