An issue was discovered on TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices. OS command injection occurs through the get_set.ccp lanHostCfg_HostName_1.1.1.0.0 parameter.
2019-12-18T15:15:10.803
2024-11-21T04:21:01.877
Modified
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | trendnet | tew-651br_firmware | 2.04b1 | Yes |
Hardware | trendnet | tew-651br | - | No |
Operating System | trendnet | tew-652brp_firmware | 3.04b01 | Yes |
Hardware | trendnet | tew-652brp | - | No |
Operating System | trendnet | tew-652bru_firmware | 1.00b12 | Yes |
Hardware | trendnet | tew-652bru | - | No |