Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /goform/SetOnlineDevName.
- https://github.com/ef4tless/vuln/blob/master/iot/AX12/SetOnlineDevName.md
No PoCs found on GitHub currently.