Tenda O3V2 v1.0.0.12(3880) was discovered to contain a Blind Command Injection via stpEn parameter in the SetStp function. This vulnerability allows attackers to execute arbitrary commands with root privileges.
| Software | From | Fixed in |
|---|---|---|
| tenda / o3_firmware | 1.0.0.12(3880) | 1.0.0.12(3880).x |