CVE-2022-36587: Buffer Overflow
Published Sep 7, 2022
·Updated
In Tenda G3 USG3V3.0brV15.11.0.6(7663)ENTDE, there is a buffer overflow vulnerability caused by sprintf in function in the httpd binary.
Affected Software
4 affected components
Tenda G3 Firmware=15.11.0.6\(7663\)
Tenda G3
All of the following
Tenda G3 Firmware=15.11.0.6\(7663\)
Tenda G3
Remediation
Patch Available
Event History
Sep 7, 2022
CVE Published
via MITRE·04:31 PM
Data Sourced
via MITRE·04:31 PM
Description
Data Sourced
via NVD·05:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-36587?
CVE-2022-36587 is classified as a high severity vulnerability due to its potential to lead to remote code execution.
2
How do I fix CVE-2022-36587?
To fix CVE-2022-36587, update the Tenda G3 firmware to a version that addresses the buffer overflow issue.
3
What causes the vulnerability CVE-2022-36587?
CVE-2022-36587 is caused by a buffer overflow resulting from improper use of the sprintf function in the httpd binary.
4
What devices are affected by CVE-2022-36587?
CVE-2022-36587 affects Tenda G3 devices running the firmware version 15.11.0.6 (7663).
5
Is CVE-2022-36587 an easily exploitable vulnerability?
Yes, CVE-2022-36587 is considered easily exploitable, allowing attackers to execute arbitrary code on affected devices.