PT-2024-1396 · Trendnet · Trendnet Tew-800Mb

·

CVE-2024-0918

·

Published

2024-01-26

·

Updated

2024-05-17

CVSS v2.0

8.3

High

VectorAV:N/AC:L/Au:M/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions TRENDnet TEW-800MB version 1.0.1.0
Description A critical issue was found in the component POST Request Handler, where the manipulation of the DeviceURL argument leads to os command injection. This allows an attacker to execute arbitrary commands or cause a denial of service. The attack can be launched remotely.
Recommendations For TRENDnet TEW-800MB version 1.0.1.0, as a temporary workaround, consider restricting access to the POST Request Handler component until a patch is available. Avoid using the DeviceURL argument in the affected component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-00862
CVE-2024-0918

Affected Products

Trendnet Tew-800Mb