Lucene search

K
nvd[email protected]NVD:CVE-2024-36604
HistoryJun 04, 2024 - 7:20 p.m.

CVE-2024-36604

2024-06-0419:20:13
CWE-77
web.nvd.nist.gov
tenda o3v2
blind command injection
root privileges

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

8.1 High

AI Score

Confidence

High

0 Low

EPSS

Percentile

0.0%

Tenda O3V2 v1.0.0.12(3880) was discovered to contain a Blind Command Injection via stpEn parameter in the SetStp function. This vulnerability allows attackers to execute arbitrary commands with root privileges.

Affected configurations

NVD
Node
tendacno3v2_firmwareMatch1.0.0.12\(3880\)
AND
tendacno3v2Match-

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

8.1 High

AI Score

Confidence

High

0 Low

EPSS

Percentile

0.0%

Related for NVD:CVE-2024-36604