TRENDnet TEW-632BRP v1.010B31 devices have an OS command injection vulnerability in the CGl interface "ntp_sync.cgi",which allows remote attackers to execute arbitrary commands via parameter "ntp_server" passed to the "ntp_sync.cgi" binary through a POST request.
2025-01-27T15:15:11.463
2025-05-29T16:01:22.487
Analyzed
CVSSv3.1: 9.8 (CRITICAL)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | trendnet | tew-632brp_firmware | 1.010b31 | Yes |
Hardware | trendnet | tew-632brp | - | No |