Vulnerabilities (CVE)

Filtered by vendor Trendnet Subscribe
Total 190 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-15139 1 Trendnet 2 Tew-822dre, Tew-822dre Firmware 2026-06-17 6.5 MEDIUM 6.3 MEDIUM
A vulnerability has been found in TRENDnet TEW-822DRE 1.00B21/1.01B06. This affects the function sub_43ACF4  of the file /boafrm/formWsc. Such manipulation of the argument peerPin leads to command injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2025-15137 1 Trendnet 2 Tew-800mb, Tew-800mb Firmware 2026-06-17 9.0 HIGH 8.8 HIGH
A vulnerability was detected in TRENDnet TEW-800MB 1.0.1.0. Affected by this vulnerability is the function sub_F934  of the file NTPSyncWithHost.cgi. The manipulation results in command injection. The attack may be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2025-15136 1 Trendnet 2 Tew-800mb, Tew-800mb Firmware 2026-06-17 9.0 HIGH 8.8 HIGH
A security vulnerability has been detected in TRENDnet TEW-800MB 1.0.1.0. Affected is the function do_setWizard_asp of the file /goform/wizardset of the component Management Interface. The manipulation of the argument WizardConfigured leads to command injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2024-57590 1 Trendnet 2 Tew-632brp, Tew-632brp Firmware 2026-06-17 N/A 9.8 CRITICAL
TRENDnet TEW-632BRP v1.010B31 devices have an OS command injection vulnerability in the CGl interface "ntp_sync.cgi",which allows remote attackers to execute arbitrary commands via parameter "ntp_server" passed to the "ntp_sync.cgi" binary through a POST request.
CVE-2024-51190 1 Trendnet 6 Tew-651br, Tew-651br Firmware, Tew-652brp and 3 more 2026-06-17 N/A 4.8 MEDIUM
TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS) vulnerability via the ptRule_ApplicationName_1.1.6.0.0 parameter on the /special_ap.htm page.
CVE-2024-51189 1 Trendnet 6 Tew-651br, Tew-651br Firmware, Tew-652brp and 3 more 2026-06-17 N/A 4.8 MEDIUM
TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS) vulnerability via the macList_Name_1.1.1.0.0 parameter on the /filters.htm page.
CVE-2024-51188 1 Trendnet 6 Tew-651br, Tew-651br Firmware, Tew-652brp and 3 more 2026-06-17 N/A 4.8 MEDIUM
TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS) vulnerability via the vsRule_VirtualServerName_1.1.10.0.0 parameter on the /virtual_server.htm page.
CVE-2024-51187 1 Trendnet 6 Tew-651br, Tew-651br Firmware, Tew-652brp and 3 more 2026-06-17 N/A 4.8 MEDIUM
TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS) vulnerability via the firewallRule_Name_1.1.1.0.0 parameter on the /firewall_setting.htm page.
CVE-2024-50667 1 Trendnet 2 Tew-820ap, Tew-820ap Firmware 2026-06-17 N/A 9.8 CRITICAL
The boa httpd of Trendnet TEW-820AP 1.01.B01 has a stack overflow vulnerability in /boafrm/formIPv6Addr, /boafrm/formIpv6Setup, /boafrm/formDnsv6. The reason is that the check of ipv6 address is not sufficient, which allows attackers to construct payloads for attacks.
CVE-2024-42813 1 Trendnet 2 Tew-752dru, Tew-752dru Firmware 2026-06-17 N/A 9.8 CRITICAL
In TRENDnet TEW-752DRU FW1.03B01, there is a buffer overflow vulnerability due to the lack of length verification for the service field in gena.cgi. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands.
CVE-2024-37645 1 Trendnet 2 Tew-814dap, Tew-814dap Firmware 2026-06-17 N/A 8.8 HIGH
TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a stack overflow vulnerability via the submit-url parameter at /formSysLog .
CVE-2024-37644 1 Trendnet 2 Tew-814dap, Tew-814dap Firmware 2026-06-17 N/A 8.8 HIGH
TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in as root.
CVE-2024-37643 1 Trendnet 2 Tew-814dap, Tew-814dap Firmware 2026-06-17 N/A 8.8 HIGH
TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a stack overflow vulnerability via the submit-url parameter at /formPasswordAuth .
CVE-2024-37642 1 Trendnet 2 Tew-814dap, Tew-814dap Firmware 2026-06-17 N/A 9.1 CRITICAL
TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a command injection vulnerability via the ipv4_ping, ipv6_ping parameter at /formSystemCheck .
CVE-2024-37641 1 Trendnet 2 Tew-814dap, Tew-814dap Firmware 2026-06-17 N/A 8.8 HIGH
TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a stack overflow via the submit-url parameter at /formNewSchedule
CVE-2024-36729 1 Trendnet 2 Tew-827dru, Tew-827dru Firmware 2026-06-17 N/A 6.3 MEDIUM
TRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows an authenticated user to execute arbitrary code by POSTing to apply.cgi via the action wizard_ipv6 with a sufficiently long reboot_type key.
CVE-2024-36728 1 Trendnet 2 Tew-827dru, Tew-827dru Firmware 2026-06-17 N/A 8.1 HIGH
TRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows an authenticated user to execute arbitrary code by POSTing to apply.cgi via the action vlan_setting with a sufficiently long dns1 or dns 2 key.
CVE-2024-28354 1 Trendnet 2 Tew-827dru, Tew-827dru Firmware 2026-06-17 N/A 10.0 CRITICAL
There is a command injection vulnerability in the TRENDnet TEW-827DRU router with firmware version 2.10B01. An attacker can inject commands into the post request parameters usapps.@smb[%d].username in the apply.cgi interface, thereby gaining root shell privileges.
CVE-2024-28353 1 Trendnet 2 Tew-827dru, Tew-827dru Firmware 2026-06-17 N/A 8.8 HIGH
There is a command injection vulnerability in the TRENDnet TEW-827DRU router with firmware version 2.10B01. An attacker can inject commands into the post request parameters usapps.config.smb_admin_name in the apply.cgi interface, thereby gaining root shell privileges.
CVE-2024-22546 1 Trendnet 2 Tew-815dap, Tew-815dap Firmware 2026-06-17 N/A 6.4 MEDIUM
TRENDnet TEW-815DAP 1.0.2.0 is vulnerable to Command Injection via the do_setNTP function. An authenticated attacker with administrator privileges can leverage this vulnerability over the network via a malicious POST request.