Tenda G3 Firmware vulnerabilities
24 known vulnerabilities affecting tenda/g3_firmware.
Total CVEs
24
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL9HIGH15
Vulnerabilities
Page 2 of 2
CVE-2022-36584CRITICALCVSS 9.8v15.11.0.6\(7663\)2022-09-06
CVE-2022-36584 [CRITICAL] CWE-120 CVE-2022-36584: In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, the getsinglepppuser function has a buffer overflow
In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, the getsinglepppuser function has a buffer overflow caused by sscanf.
nvd
CVE-2021-27706CRITICALCVSS 9.8vv15.11.0.17\(9502\)_cn2021-04-14
CVE-2021-27706 [CRITICAL] CWE-120 CVE-2021-27706: Buffer Overflow in Tenda G1 and G3 routers with firmware version V15.11.0.17(9502)_CN allows remote
Buffer Overflow in Tenda G1 and G3 routers with firmware version V15.11.0.17(9502)_CN allows remote attackers to execute arbitrary code via a crafted action/"IPMacBindIndex "request. This occurs because the "formIPMacBindDel" function directly passes the parameter "IPMacBindIndex" to strcpy without limit.
nvd
CVE-2021-27707CRITICALCVSS 9.8vv15.11.0.17\(9502\)_cn2021-04-14
CVE-2021-27707 [CRITICAL] CWE-120 CVE-2021-27707: Buffer Overflow in Tenda G1 and G3 routers with firmware v15.11.0.17(9502)_CN allows remote attacker
Buffer Overflow in Tenda G1 and G3 routers with firmware v15.11.0.17(9502)_CN allows remote attackers to execute arbitrary code via a crafted action/"portMappingIndex "request. This occurs because the "formDelPortMapping" function directly passes the parameter "portMappingIndex" to strcpy without limit.
nvd
CVE-2021-27705CRITICALCVSS 9.8vv15.11.0.17\(9502\)_cn2021-04-14
CVE-2021-27705 [CRITICAL] CWE-120 CVE-2021-27705: Buffer Overflow in Tenda G1 and G3 routers with firmware v15.11.0.17(9502)_CN allows remote attacker
Buffer Overflow in Tenda G1 and G3 routers with firmware v15.11.0.17(9502)_CN allows remote attackers to execute arbitrary code via a crafted action/"qosIndex "request. This occurs because the "formQOSRuleDel" function directly passes the parameter "qosIndex" to strcpy without limit.
nvd
← Previous2 / 2