PT-2026-1521 · Trendnet · Trendnet Tew-713Re
Zephyr369
·
Published
2026-01-06
·
Updated
2026-02-12
·
CVE-2025-15471
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
TRENDnet TEW-713RE version 1.02
Description
A flaw exists in TRENDnet TEW-713RE that allows for remote operating system command injection. The issue is located in the
/goformX/formFSrvX file, specifically through manipulation of the SZCMD parameter. Successful exploitation allows attackers to execute arbitrary commands on the system. The exploit is publicly available. The vendor was notified of the issue but did not provide a response.Recommendations
TRENDnet TEW-713RE version 1.02: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Command Injection
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Trendnet Tew-713Re