CVE-2024-36604: Command Injection
Tenda O3V2 v1.0.0.12(3880) was discovered to contain a Blind Command Injection via stpEn parameter in the SetStp function. This vulnerability allows attackers to execute arbitrary commands with root privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-36604?
CVE-2024-36604 has a critical severity rating due to the ability for attackers to execute arbitrary commands with root privileges.
How do I fix CVE-2024-36604?
To fix CVE-2024-36604, update the Tenda O3 firmware to a patched version that addresses the Blind Command Injection vulnerability.
What devices are affected by CVE-2024-36604?
CVE-2024-36604 specifically affects Tenda O3 devices running firmware version 1.0.0.12(3880).
What type of vulnerability is CVE-2024-36604?
CVE-2024-36604 is categorized as a Blind Command Injection vulnerability found in the SetStp function.
Can CVE-2024-36604 allow remote attacks?
Yes, CVE-2024-36604 can potentially allow remote attackers to execute commands due to its nature of Blind Command Injection.