Trendnet
trendnet
190 CVEs • 129 products
Products (129)
Click to collapseToggle
Products (129)
Click to collapse
CVEs (190)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Trendnet 4Tew 755ap2kac Firmware Tew 755ap FirmwareTew 821dap2kac Firmware+1 moreJun 17, 2026 Aug 10, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Null Pointer Deference vulnerability exists in TRENDnet TEW-755AP 1.11B03, TEW-755AP2KAC 1.11B03, TEW-821DAP2KAC 1.11B03, and TEW-825DAP 1.11B03, which could let a remote malicious user cause a denial os service by sendi...Show more |
1Trendnet 4Tew 755ap2kac Firmware Tew 755ap FirmwareTew 821dap2kac Firmware+1 moreJun 17, 2026 Aug 10, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Null Pointer Dereference vulnerability in TRENDnet TEW-755AP 1.11B03, TEW-755AP2KAC 1.11B03, TEW-821DAP2KAC 1.11B03, and TEW-825DAP 1.11B03, which could let a remote malicious user cause a denial of service by sending a...Show more |
1Trendnet 1Tv Ip110wn Firmware Jul 9, 2026 Aug 10, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross Site Scripting (XSS) vulnerability in TRENDnet TV-IP110WN V1.2.2.64 V1.2.2.65 V1.2.2.68 via the profile parameter. in a GET request in view.cgi. |
1Trendnet 1Tw100 S4w1ca Firmware Jun 17, 2026 Jun 17, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In TrendNet TW100-S4W1CA 2.3.32, it is possible to inject arbitrary JavaScript into the router's web interface via the "echo" command. |
1Trendnet 1Tw100 S4w1ca Firmware Jun 17, 2026 Jun 17, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 In TrendNet TW100-S4W1CA 2.3.32, due to a lack of proper session controls, a threat actor could make unauthorized changes to an affected router via a specially crafted web page. If an authenticated user were to interact...Show more |
1Trendnet 1Tew 827dru Firmware Jun 17, 2026 Jun 15, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 TRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows an authenticated user to execute arbitrary code by POSTing to apply.cgi via the action st_dev_conne...Show more |
TRENDnet TEW-827DRU devices through 2.06B04 contain multiple command injections in apply.cgi via the action send_log_email with the key auth_acname (or auth_passwd), allowing an authenticated user to run arbitrary comman...Show more |
1Trendnet 1Tew 827dru Firmware Jun 17, 2026 Jun 15, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 TRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows an unauthenticated user to execute arbitrary code by POSTing to apply_sec.cgi via the action ping_t...Show more |
1Trendnet 1Tew 827dru Firmware Jun 17, 2026 Jun 15, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 TRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows an authenticated user to execute arbitrary code by POSTing to apply.cgi via the action auto_up_fw (...Show more |
1Trendnet 1Tew 827dru Firmware Jun 17, 2026 Jun 15, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 TRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows an authenticated user to execute arbitrary code by POSTing to apply.cgi via the action wifi_captive...Show more |
1Trendnet 1Tew 827dru Firmware Jun 17, 2026 Jun 15, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 TRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows an authenticated user to execute arbitrary code by POSTing to apply.cgi via the action set_sta_enro...Show more |
TRENDnet TEW-827DRU devices through 2.06B04 contain multiple command injections in apply.cgi via the action pppoe_connect, ru_pppoe_connect, or dhcp_connect with the key wan_ifname (or wan0_dns), allowing an authenticate...Show more |
1Trendnet 1Tew 827dru Firmware Jun 17, 2026 Jun 15, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 TRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows an authenticated user to execute arbitrary code by POSTing to apply.cgi via the action kick_ban_wif...Show more |
1Trendnet 1Tv Ip512wn Firmware Jun 17, 2026 May 13, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 TRENDnet ProView Wireless camera TV-IP512WN 1.0R 1.0.4 is vulnerable to an unauthenticated stack-based buffer overflow in handling RTSP packets. This may result in remote code execution or denial of service. The issue is...Show more |
2Dlink Trendnet2Dir 825 Firmware Tew 632brp FirmwareJun 17, 2026 Mar 7, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the date parameter in a system_time.cgi POST request. TRENDnet TEW-632BRP 1.010B32 is also affec...Show more |
2Dlink Trendnet2Dir 825 Firmware Tew 632brp FirmwareJun 17, 2026 Mar 7, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the dns_query_name parameter in a dns_query.cgi POST request. TRENDnet TEW-632BRP 1.010B32 is al...Show more |
2Dlink Trendnet2Dir 825 Firmware Tew 632brp FirmwareJun 17, 2026 Mar 7, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands via the wps_sta_enrollee_pin parameter in a set_sta_enrollee_pin.cgi POST request. TRENDnet TEW-632B...Show more |
TRENDnet TS-S402 has a backdoor to enable TELNET. |
1Trendnet 3Tew 651br Firmware Tew 652brp FirmwareTew 652bru FirmwareJun 17, 2026 Dec 18, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered on TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices. A buffer overflow occurs through the get_set.ccp ccp_act parameter. |
1Trendnet 3Tew 651br Firmware Tew 652brp FirmwareTew 652bru FirmwareJun 17, 2026 Dec 18, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered on TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices. OS command injection occurs through the get_set.ccp lanHostCfg_HostName_1.1.1.0.0 parameter. |