PT-2023-16402 · Trendnet · Trendnet Tew-811Dru

Leetsun

·

Published

2023-02-01

·

Updated

2024-05-17

·

CVE-2023-0613

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions TRENDnet TEW-811DRU version 1.0.10.0
Description A critical vulnerability has been found in the httpd component of the TRENDnet TEW-811DRU, specifically affecting an unknown functionality of the file /wireless/security.asp. The manipulation of the device web ip argument leads to memory corruption. This issue can be exploited remotely. There have been reports of elevated activities targeting this vulnerability.
Recommendations For TRENDnet TEW-811DRU version 1.0.10.0, as a temporary workaround, consider restricting access to the /wireless/security.asp file until a patch is available. Additionally, avoid manipulating the device web ip argument in the affected component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2023-0613

Affected Products

Trendnet Tew-811Dru