CVE-2024-36604: Tenda o3 Firmware
Critical severity, CVSS 9.8. EPSS: 2% chance of exploitation in the next 30 days.
Tenda O3V2 v1.0.0.12(3880) was discovered to contain a Blind Command Injection via stpEn parameter in the SetStp function. This vulnerability allows attackers to execute arbitrary commands with root privileges.
Affected products
- Tenda o3 Firmware: version 1.0.0.12(3880) only
Published 2024-06-04. Last modified 2026-06-17.