PT-2024-1396 · Trendnet · Trendnet Tew-800Mb
CVSS v2.0
8.3
High
| Vector | AV:N/AC:L/Au:M/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
TRENDnet TEW-800MB version 1.0.1.0
Description
A critical issue was found in the component POST Request Handler, where the manipulation of the
DeviceURL argument leads to os command injection. This allows an attacker to execute arbitrary commands or cause a denial of service. The attack can be launched remotely.Recommendations
For TRENDnet TEW-800MB version 1.0.1.0, as a temporary workaround, consider restricting access to the POST Request Handler component until a patch is available. Avoid using the
DeviceURL argument in the affected component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Trendnet Tew-800Mb