CVE-2022-36585

Severity CVSS v4.0:
Pending analysis
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
07/09/2022
Last modified:
09/09/2022

Description

In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, in httpd binary, the addDhcpRule function has a buffer overflow caused by sscanf.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:tenda:g3_firmware:15.11.0.6\(7663\):*:*:*:*:*:*:*
cpe:2.3:h:tenda:g3:-:*:*:*:*:*:*:*