← Back to browse · API

CVE-2024-36604

Severity
CRITICAL
CVSS
9.8
EPSS
0.01975
Risk score
39.89
CISA KEV
No
PoC
No
Published
2024-06-04
Modified
2025-02-13
First seen
2026-08-07
Aliases
EUVD-2024-36171, GHSA-5WC3-V5J6-M54X
Products
n/a:n/a n/a
Sources
euvd EUVD-2024-36171

Description

Tenda O3V2 v1.0.0.12(3880) was discovered to contain a Blind Command Injection via stpEn parameter in the SetStp function. This vulnerability allows attackers to execute arbitrary commands with root privileges.

References