CVE-2022-36586
https://notcve.org/view.php?id=CVE-2022-36586
In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, there is a buffer overflow vulnerability caused by strcpy in function 0x869f4 in the httpd binary. En Tenda G3 versiones US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, se presenta una vulnerabilidad de desbordamiento de búfer causada por strcpy en la función 0x869f4 en el binario httpd • https://github.com/Davidteeri/Bug-Report/blob/main/tenda-G3-%200x869f4.md https://www.tendacn.com/download/detail-3401.html • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •
CVE-2022-36585
https://notcve.org/view.php?id=CVE-2022-36585
In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, in httpd binary, the addDhcpRule function has a buffer overflow caused by sscanf. En Tenda G3 versión US_G3V3.0br_V15.11.0.6(7663)_ES_TDE, en el binario httpd, la función addDhcpRule presenta un desbordamiento de búfer causado por sscanf • https://github.com/Davidteeri/Bug-Report/blob/main/tenda-G3-0x62158.md https://www.tendacn.com/download/detail-3401.html • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •
CVE-2022-36587
https://notcve.org/view.php?id=CVE-2022-36587
In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, there is a buffer overflow vulnerability caused by sprintf in function in the httpd binary. En Tenda G3 versión US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, se presenta una vulnerabilidad de desbordamiento de búfer causada por sprintf en la función del binario httpd • https://github.com/Davidteeri/Bug-Report/blob/main/tenda-G3-%200x53208.md https://www.tendacn.com/download/detail-3401.html • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •
CVE-2022-36584
https://notcve.org/view.php?id=CVE-2022-36584
In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, the getsinglepppuser function has a buffer overflow caused by sscanf. En Tenda G3 versión US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, la función getsinglepppuser presenta un desbordamiento de búfer causado por sscanf. • https://github.com/Davidteeri/Bug-Report/blob/main/tenda-G3-bug1.md https://www.tendacn.com/download/detail-3401.html • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •
CVE-2021-27707
https://notcve.org/view.php?id=CVE-2021-27707
Buffer Overflow in Tenda G1 and G3 routers with firmware v15.11.0.17(9502)_CN allows remote attackers to execute arbitrary code via a crafted action/"portMappingIndex "request. This occurs because the "formDelPortMapping" function directly passes the parameter "portMappingIndex" to strcpy without limit. Un desbordamiento de búfer en los enrutadores Tenda versiones G1 y G3 con firmware v15.11.0.17(9502) _CN, permite a atacantes remotos ejecutar código arbitrario por medio de una petición diseñada action/"portMappingIndex". Esto ocurre porque la función "formDelPortMapping" pasa directamente el parámetro "portMappingIndex" a strcpy sin límite • https://hackmd.io/U7OVgYIuRcOKV7SW5-euHw • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •