← Vulnerability feed

Vulnerability record · CVE-2022-36586 · published 8 September 2022

CVE-2022-36586: Tenda g3 firmware classic buffer overflow vulnerability

Tenda · G3 Firmware

In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, there is a buffer overflow vulnerability caused by strcpy in function 0x869f4 in the httpd binary.

9.8 CVSS 3.1 Critical EPSS 0.94% · top 40.5% CWE-120 · Classic buffer overflow
9.8CVSS 3.1 base score
0.94%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, there is a buffer overflow vulnerability caused by strcpy in function 0x869f4 in the httpd binary.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-36586 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-4165Tenda g3 firmware stack-based buffer overflow vulnerabilityA vulnerability, which was classified as critical, was found in Tenda G3 15.11.0.17(9502). Affected is the function modifyDhcpRule of the file /gofor…EPSS 1.5%9.8CVE-2024-4164Tenda g3 firmware stack-based buffer overflow vulnerabilityA vulnerability, which was classified as critical, has been found in Tenda G3 15.11.0.17(9502). This issue affects the function formModifyPppAuthWhit…EPSS 1.5%9.8CVE-2022-36585Tenda g3 firmware classic buffer overflow vulnerabilityIn Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, in httpd binary, the addDhcpRule function has a buffer overflow caused by sscanf.EPSS 0.94%9.8CVE-2022-36587Tenda g3 firmware classic buffer overflow vulnerabilityIn Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, there is a buffer overflow vulnerability caused by sprintf in function in the httpd binary.EPSS 0.94%9.8CVE-2022-36584Tenda g3 firmware classic buffer overflow vulnerabilityIn Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, the getsinglepppuser function has a buffer overflow caused by sscanf.EPSS 0.94%9.8CVE-2021-27706Tenda g1 firmware classic buffer overflow vulnerabilityBuffer Overflow in Tenda G1 and G3 routers with firmware version V15.11.0.17(9502)_CN allows remote attackers to execute arbitrary code via a crafted…EPSS 2.8%9.8CVE-2021-27707Tenda g1 firmware classic buffer overflow vulnerabilityBuffer Overflow in Tenda G1 and G3 routers with firmware v15.11.0.17(9502)_CN allows remote attackers to execute arbitrary code via a crafted action/…EPSS 2.8%9.8CVE-2021-27705Tenda g1 firmware classic buffer overflow vulnerabilityBuffer Overflow in Tenda G1 and G3 routers with firmware v15.11.0.17(9502)_CN allows remote attackers to execute arbitrary code via a crafted action/…EPSS 2.9%

Source: NIST National Vulnerability Database (record CVE-2022-36586), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.