CVE-2022-36585: Buffer Overflow
Published Sep 7, 2022
·Updated
In Tenda G3 USG3V3.0brV15.11.0.6(7663)ENTDE, in httpd binary, the addDhcpRule function has a buffer overflow caused by sscanf.
Affected Software
2 affected components
Tenda G3 Firmware=15.11.0.6\(7663\)
Tenda G3
Remediation
Patch Available
Event History
Sep 7, 2022
CVE Published
via MITRE·10:55 PM
Data Sourced
via MITRE·10:55 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-36585?
CVE-2022-36585 is considered to have a medium severity due to the buffer overflow vulnerability in the Tenda G3 firmware.
2
How do I fix CVE-2022-36585?
To fix CVE-2022-36585, update the Tenda G3 firmware to version 15.11.0.6(7663) or later.
3
What systems are affected by CVE-2022-36585?
CVE-2022-36585 affects the Tenda G3 router running firmware version 15.11.0.6(7663).
4
What is a buffer overflow in the context of CVE-2022-36585?
A buffer overflow in CVE-2022-36585 refers to a flaw in the addDhcpRule function that can allow arbitrary code execution or unexpected behavior.
5
Is there a workaround for CVE-2022-36585 if I cannot update immediately?
There are no official workarounds for CVE-2022-36585; immediate firmware update is recommended for protection.