PT-2024-1397 · Trendnet · Trendnet Tew-822Dre

Sonicrr

·

Published

2024-01-26

·

Updated

2024-05-17

·

CVE-2024-0920

CVSS v2.0

8.3

High

VectorAV:N/AC:L/Au:M/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions TRENDnet TEW-822DRE version 1.03B02
Description A critical issue affects the file /admin ping.htm of the component POST Request Handler. The manipulation of the ipv4 ping/ipv6 ping argument leads to command injection. This can be initiated remotely. The issue has been publicly disclosed and may be exploited.
Recommendations For TRENDnet TEW-822DRE version 1.03B02, as a temporary workaround, consider restricting access to the /admin ping.htm file until a patch is available. Avoid using the ipv4 ping and ipv6 ping arguments in the affected POST Request Handler until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2024-00863
CVE-2024-0920

Affected Products

Trendnet Tew-822Dre