First published: Tue Jun 04 2024(Updated: )
Tenda O3V2 v1.0.0.12(3880) was discovered to contain a Blind Command Injection via stpEn parameter in the SetStp function. This vulnerability allows attackers to execute arbitrary commands with root privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Tenda O3 | =1.0.0.12\(3880\) | |
Tenda O3v2 Firmware | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-36604 has a critical severity rating due to the ability for attackers to execute arbitrary commands with root privileges.
To fix CVE-2024-36604, update the Tenda O3 firmware to a patched version that addresses the Blind Command Injection vulnerability.
CVE-2024-36604 specifically affects Tenda O3 devices running firmware version 1.0.0.12(3880).
CVE-2024-36604 is categorized as a Blind Command Injection vulnerability found in the SetStp function.
Yes, CVE-2024-36604 can potentially allow remote attackers to execute commands due to its nature of Blind Command Injection.