CVE-2025-15472

A flaw has been found in TRENDnet TEW-811DRU 1.0.2.0. This affects the function setDeviceURL  of the file uapply.cgi of the component httpd . This manipulation of the argument DeviceURL causes os command injection. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
References
Link Resource
https://pentagonal-time-3a7.notion.site/TrendNet-TEW-811DRU-2d2e5dd4c5a58016a612e99853b835f8 Exploit Third Party Advisory
https://vuldb.com/?ctiid.339722 Permissions Required VDB Entry
https://vuldb.com/?id.339722 Third Party Advisory VDB Entry
https://vuldb.com/?submit.721874 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:trendnet:tew-811dru_firmware:1.0.2.0:*:*:*:*:*:*:*
cpe:2.3:h:trendnet:tew-811dru:-:*:*:*:*:*:*:*

History

15 Jan 2026, 22:16

Type Values Removed Values Added
CPE cpe:2.3:o:trendnet:tew-811dru_firmware:1.0.2.0:*:*:*:*:*:*:*
cpe:2.3:h:trendnet:tew-811dru:-:*:*:*:*:*:*:*
First Time Trendnet
Trendnet tew-811dru Firmware
Trendnet tew-811dru
References () https://pentagonal-time-3a7.notion.site/TrendNet-TEW-811DRU-2d2e5dd4c5a58016a612e99853b835f8 - () https://pentagonal-time-3a7.notion.site/TrendNet-TEW-811DRU-2d2e5dd4c5a58016a612e99853b835f8 - Exploit, Third Party Advisory
References () https://vuldb.com/?ctiid.339722 - () https://vuldb.com/?ctiid.339722 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.339722 - () https://vuldb.com/?id.339722 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.721874 - () https://vuldb.com/?submit.721874 - Third Party Advisory, VDB Entry

07 Jan 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-07 12:16

Updated : 2026-01-15 22:16


NVD link : CVE-2025-15472

Mitre link : CVE-2025-15472

CVE.ORG link : CVE-2025-15472


JSON object : View

Products Affected

trendnet

  • tew-811dru
  • tew-811dru_firmware
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')