CVE-2024-39963: Tenda AX12 Firmware

High severity, CVSS 8.0. EPSS: 1.5% chance of exploitation in the next 30 days.

AX3000 Dual-Band Gigabit Wi-Fi 6 Router AX9 V22.03.01.46 and AX3000 Dual-Band Gigabit Wi-Fi 6 Router AX12 V1.0 V22.03.01.46 were discovered to contain an authenticated remote command execution (RCE) vulnerability via the macFilterType parameter at /goform/setMacFilterCfg.

Affected products

  • Tenda AX12 Firmware: version 22.03.01.46 only
  • Tenda AX9 Firmware: version 22.03.01.46 only

Published 2024-07-19. Last modified 2026-06-17.