PT-2025-32446 · Lighttpd+1 · Lighttpd+1

Tpchecker

·

Published

2025-07-29

·

Updated

2026-01-02

·

CVE-2025-8759

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: TRENDnet TN-200 version 1.02b02
Description: A vulnerability exists in the TRENDnet TN-200 device. The issue resides in the Lighttpd component, where manipulation of the secdownload.secret argument with the input neV3rUseMe results in the use of a hard-coded cryptographic key. This issue can be exploited remotely, but the attack complexity is considered high and exploitation appears difficult. The exploit has been publicly disclosed. The vendor was informed of the disclosure but did not respond.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

BDU:2025-09644
CVE-2025-8759

Affected Products

Lighttpd
Trendnet Tn-200