CVE-2023-51812: Tenda AX3 Firmware

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

Tenda AX3 v16.03.12.11 was discovered to contain a remote code execution (RCE) vulnerability via the list parameter at /goform/SetNetControlList.

Affected products

  • Tenda AX3 Firmware: version 16.03.12.11 only

Published 2024-01-04. Last modified 2026-06-17.