Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-49031 | A vulnerability, which was classified as critical, was found in Tenda G3 15.11.0.20. Affected is the function formSetSysTime of the file /goform/SetSysTimeCfg. The manipulation of the argument sysTimePolicy leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. |
Thu, 29 Aug 2024 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tenda g3
|
|
| Weaknesses | CWE-787 | |
| CPEs | cpe:2.3:h:tenda:g3:-:*:*:*:*:*:*:* cpe:2.3:o:tenda:g3_firmware:15.11.0.20:*:*:*:*:*:*:* |
|
| Vendors & Products |
Tenda g3
|
Wed, 28 Aug 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tenda
Tenda g3 Firmware |
|
| CPEs | cpe:2.3:o:tenda:g3_firmware:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Tenda
Tenda g3 Firmware |
|
| Metrics |
ssvc
|
Tue, 27 Aug 2024 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability, which was classified as critical, was found in Tenda G3 15.11.0.20. Affected is the function formSetSysTime of the file /goform/SetSysTimeCfg. The manipulation of the argument sysTimePolicy leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | Tenda G3 SetSysTimeCfg formSetSysTime stack-based overflow | |
| Weaknesses | CWE-121 | |
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2024-08-28T13:57:49.602Z
Reserved: 2024-08-27T13:12:02.503Z
Link: CVE-2024-8225
Updated: 2024-08-28T13:57:35.473Z
Status : Analyzed
Published: 2024-08-27T23:15:04.207
Modified: 2024-08-29T00:14:43.957
Link: CVE-2024-8225
No data.
OpenCVE Enrichment
No data.
EUVD