PT-2024-27092 · Tenda · Tenda O3V2

Published

2024-06-04

·

Updated

2024-12-13

·

CVE-2024-36604

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tenda O3V2 version 1.0.0.12(3880)
Description The issue is related to a Blind Command Injection via the stpEn parameter in the SetStp function, allowing attackers to execute arbitrary commands with root privileges.
Recommendations For Tenda O3V2 version 1.0.0.12(3880), consider disabling the SetStp function or restricting access to the stpEn parameter to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2024-36604

Affected Products

Tenda O3V2