PT-2023-16402 · Trendnet · Trendnet Tew-811Dru
Leetsun
·
Published
2023-02-01
·
Updated
2024-05-17
·
CVE-2023-0613
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
TRENDnet TEW-811DRU version 1.0.10.0
Description
A critical vulnerability has been found in the httpd component of the TRENDnet TEW-811DRU, specifically affecting an unknown functionality of the file /wireless/security.asp. The manipulation of the
device web ip argument leads to memory corruption. This issue can be exploited remotely. There have been reports of elevated activities targeting this vulnerability.Recommendations
For TRENDnet TEW-811DRU version 1.0.10.0, as a temporary workaround, consider restricting access to the /wireless/security.asp file until a patch is available. Additionally, avoid manipulating the
device web ip argument in the affected component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Trendnet Tew-811Dru