A vulnerability, which was classified as critical, was found in Tenda O3V2 1.0.0.12(3880). Affected is the function fromSysToolTime of the file /goform/setSysTimeInfo of the component httpd. The manipulation of the argument Time leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Metrics
Affected Vendors & Products
References
History
Wed, 16 Jul 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tenda
Tenda o3 Tenda o3 Firmware |
|
| CPEs | cpe:2.3:h:tenda:o3:2.0:*:*:*:*:*:*:* cpe:2.3:o:tenda:o3_firmware:1.0.0.12\(3880\):*:*:*:*:*:*:* |
|
| Vendors & Products |
Tenda
Tenda o3 Tenda o3 Firmware |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 11 Jul 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-07-10T21:32:06.731Z
Updated: 2025-07-11T16:49:53.541Z
Reserved: 2025-07-10T07:48:29.494Z
Link: CVE-2025-7416
Updated: 2025-07-11T16:49:47.430Z
Status : Analyzed
Published: 2025-07-10T22:15:24.870
Modified: 2025-07-16T15:00:23.473
Link: CVE-2025-7416
No data.