CVE-2024-36604: Tenda o3 Firmware

Critical severity, CVSS 9.8. EPSS: 2% chance of exploitation in the next 30 days.

Tenda O3V2 v1.0.0.12(3880) was discovered to contain a Blind Command Injection via stpEn parameter in the SetStp function. This vulnerability allows attackers to execute arbitrary commands with root privileges.

Affected products

  • Tenda o3 Firmware: version 1.0.0.12(3880) only

Published 2024-06-04. Last modified 2026-06-17.