← Back

Trendnet

trendnet

190 CVEs • 129 products

Products (129)

Click to collapse
Toggle
Tew 812dru
tew-812dru
Tv Ip422w
tv-ip422w
Tv Ip422wn
tv-ip422wn
Tv Ip743sic
tv-ip743sic
Tew 731br
tew-731br
Tew 651br
tew-651br
Tew 652br
tew-652br
Tew 711br
tew-711br
Tew 810dr
tew-810dr
Tew 813dru
tew-813dru
Tew 823dru
tew-823dru
Tew 751dr
tew-751dr
Tew 752dru
tew-752dru
Tew733gr
tew733gr
Tew 673gru
tew-673gru
Tv Ip110wn
tv-ip110wn
Tv Ip121wn
tv-ip121wn
Tew 632brp
tew-632brp
Tew 827dru
tew-827dru
Tew 691gr
tew-691gr
Tew 692gr
tew-692gr
Tew 652brp
tew-652brp
Tew 652bru
tew-652bru
Ts S402
ts-s402
Tv Ip512wn
tv-ip512wn
Tw100 S4w1ca
tw100-s4w1ca
Tew 755ap
tew-755ap
Tew 755ap2kac
tew-755ap2kac
Tew 825dap
tew-825dap
Ti Pg1284i
ti-pg1284i
Ti G102i
ti-g102i
Ti G160i
ti-g160i
Ti G642i
ti-g642i
Ti Pg102i
ti-pg102i
Ti Pg541i
ti-pg541i

CVEs (190)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Trendnet
1Tew 811dru Firmware
Jun 17, 2026
Jan 7, 2026
7.3 HIGH· v4
7.2 HIGH· v3
8.3 HIGH· v2
A flaw has been found in TRENDnet TEW-811DRU 1.0.2.0. This affects the function setDeviceURL  of the file uapply.cgi of the component httpd . This manipulation of the argument DeviceURL causes os command injection. The a...Show more
A flaw has been found in TRENDnet TEW-811DRU 1.0.2.0. This affects the function setDeviceURL  of the file uapply.cgi of the component httpd . This manipulation of the argument DeviceURL causes os command injection. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Trendnet
1Tew 713re Firmware
Jun 17, 2026
Jan 7, 2026
8.9 HIGH· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A vulnerability was detected in TRENDnet TEW-713RE 1.02. The impacted element is an unknown function of the file /goformX/formFSrvX. The manipulation of the argument SZCMD results in os command injection. It is possible...Show more
A vulnerability was detected in TRENDnet TEW-713RE 1.02. The impacted element is an unknown function of the file /goformX/formFSrvX. The manipulation of the argument SZCMD results in os command injection. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor confirms: "The product in question TEW-731RE for CVE-2025-15471 has been discontinued and end of life since October 23, 2020. We no longer provide support for this product, so we are not able to confirm the vulnerabilities. We will make an announcement on the website product support page and notify customers who registered their products with us." This vulnerability only affects products that are no longer supported by the maintainer.Show less
1Trendnet
1Tew 822dre Firmware
Jun 17, 2026
Dec 28, 2025
2.1 LOW· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A vulnerability has been found in TRENDnet TEW-822DRE 1.00B21/1.01B06. This affects the function sub_43ACF4  of the file /boafrm/formWsc. Such manipulation of the argument peerPin leads to command injection. The attack c...Show more
A vulnerability has been found in TRENDnet TEW-822DRE 1.00B21/1.01B06. This affects the function sub_43ACF4  of the file /boafrm/formWsc. Such manipulation of the argument peerPin leads to command injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Trendnet
1Tew 800mb Firmware
Jun 17, 2026
Dec 28, 2025
7.4 HIGH· v4
8.8 HIGH· v3
9.0 HIGH· v2
A vulnerability was detected in TRENDnet TEW-800MB 1.0.1.0. Affected by this vulnerability is the function sub_F934  of the file NTPSyncWithHost.cgi. The manipulation results in command injection. The attack may be launc...Show more
A vulnerability was detected in TRENDnet TEW-800MB 1.0.1.0. Affected by this vulnerability is the function sub_F934  of the file NTPSyncWithHost.cgi. The manipulation results in command injection. The attack may be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Trendnet
1Tew 800mb Firmware
Jun 17, 2026
Dec 28, 2025
7.4 HIGH· v4
8.8 HIGH· v3
9.0 HIGH· v2
A security vulnerability has been detected in TRENDnet TEW-800MB 1.0.1.0. Affected is the function do_setWizard_asp of the file /goform/wizardset of the component Management Interface. The manipulation of the argument Wi...Show more
A security vulnerability has been detected in TRENDnet TEW-800MB 1.0.1.0. Affected is the function do_setWizard_asp of the file /goform/wizardset of the component Management Interface. The manipulation of the argument WizardConfigured leads to command injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Trendnet
1Tew 657brm Firmware
Jun 17, 2026
Nov 26, 2025
N/A· v4
8.0 HIGH· v3
N/A· v2
TRENDnet TEW-657BRM 1.00.1 has an authenticated remote OS command injection vulnerability in the setup.cgi binary, exploitable via the HTTP parameters "command", "todo", and "next_file," which allows an attacker to execu...Show more
TRENDnet TEW-657BRM 1.00.1 has an authenticated remote OS command injection vulnerability in the setup.cgi binary, exploitable via the HTTP parameters "command", "todo", and "next_file," which allows an attacker to execute arbitrary commands with root privileges.Show less
1Trendnet
1Tv Ip410 Firmware
Jul 5, 2026
Aug 29, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TRENDnet TV-IP410 vA1.0R was discovered to contain an OS command injection vulnerability via the /server/cgi-bin/testserv.cgi component.
1Trendnet
1Tn 200 Firmware
Jun 17, 2026
Aug 9, 2025
2.9 LOW· v4
5.9 MEDIUM· v3
2.6 LOW· v2
A vulnerability was found in TRENDnet TN-200 1.02b02. It has been declared as problematic. This vulnerability affects unknown code of the component Lighttpd. The manipulation of the argument secdownload.secret with the i...Show more
A vulnerability was found in TRENDnet TN-200 1.02b02. It has been declared as problematic. This vulnerability affects unknown code of the component Lighttpd. The manipulation of the argument secdownload.secret with the input neV3rUseMe leads to use of hard-coded cryptographic key . The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Trendnet
1Tew Wlc100p Firmware
Jul 5, 2026
Jul 21, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
In the configuration file of racoon in the TRENDnet TEW-WLC100P 2.03b03, the first item of exchage_mode is set to aggressive. Aggressive mode in IKE Phase 1 exposes identity information in plaintext, is vulnerable to off...Show more
In the configuration file of racoon in the TRENDnet TEW-WLC100P 2.03b03, the first item of exchage_mode is set to aggressive. Aggressive mode in IKE Phase 1 exposes identity information in plaintext, is vulnerable to offline dictionary attacks, and lacks flexibility in negotiating security parameters.Show less
1Trendnet
1Tpl 430ap Firmware
Jul 5, 2026
Jul 21, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
In TRENDnet TPL-430AP FW1.0, the USERLIMIT_GLOBAL option is set to 0 in the bftpd-related configuration file. This can cause DoS attacks when unlimited users are connected.
1Trendnet
1Tew Wlc100p Firmware
Jul 5, 2026
Jul 21, 2025
N/A· v4
7.3 HIGH· v3
N/A· v2
In TRENDnet TEW-WLC100P 2.03b03, the i_dont_care_about_security_and_use_aggressive_mode_psk option is enabled in the strongSwan configuration file, so that IKE Responders are allowed to use IKEv1 Aggressive Mode with Pre...Show more
In TRENDnet TEW-WLC100P 2.03b03, the i_dont_care_about_security_and_use_aggressive_mode_psk option is enabled in the strongSwan configuration file, so that IKE Responders are allowed to use IKEv1 Aggressive Mode with Pre-Shared Keys to conduct offline attacks on the openly transmitted hash of the PSK.Show less
1Trendnet
2Tew 637ap Firmware
Tew 638apb Firmware
Jun 17, 2026
Mar 30, 2025
7.1 HIGH· v4
6.5 MEDIUM· v3
6.1 MEDIUM· v2
A vulnerability classified as problematic has been found in TRENDnet TEW-637AP and TEW-638APB 1.2.7/1.3.0.106. This affects the function sub_41DED0 of the file /bin/goahead of the component HTTP Request Handler. The mani...Show more
A vulnerability classified as problematic has been found in TRENDnet TEW-637AP and TEW-638APB 1.2.7/1.3.0.106. This affects the function sub_41DED0 of the file /bin/goahead of the component HTTP Request Handler. The manipulation leads to null pointer dereference. Access to the local network is required for this attack. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Trendnet
1Tew 410apb Firmware
Jun 17, 2026
Mar 30, 2025
7.1 HIGH· v4
6.5 MEDIUM· v3
6.1 MEDIUM· v2
A vulnerability was found in TRENDnet TEW-410APB 1.3.06b. It has been rated as problematic. Affected by this issue is the function sub_4019A0 of the file /usr/sbin/httpd of the component HTTP Request Handler. The manipul...Show more
A vulnerability was found in TRENDnet TEW-410APB 1.3.06b. It has been rated as problematic. Affected by this issue is the function sub_4019A0 of the file /usr/sbin/httpd of the component HTTP Request Handler. The manipulation leads to null pointer dereference. The attack needs to be initiated within the local network. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Trendnet
1Tew 818dru Firmware
Jun 17, 2026
Mar 30, 2025
7.1 HIGH· v4
6.5 MEDIUM· v3
6.1 MEDIUM· v2
A vulnerability was found in TRENDnet TEW-818DRU 1.0.14.6. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /usr/sbin/httpd of the component HTTP Request Handler...Show more
A vulnerability was found in TRENDnet TEW-818DRU 1.0.14.6. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /usr/sbin/httpd of the component HTTP Request Handler. The manipulation leads to denial of service. The attack needs to be done within the local network. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Trendnet
1Tew 929dru Firmware
Jun 17, 2026
Feb 28, 2025
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Trendnet TEW-929DRU 1.0.0.10 contains a Stored Cross-site Scripting (XSS) vulnerability via the r_name variable inside the have_same_name function on the /addschedule.htm page.
1Trendnet
1Tew 929dru Firmware
Jun 17, 2026
Feb 28, 2025
N/A· v4
8.0 HIGH· v3
N/A· v2
TRENDnet TEW-929DRU 1.0.0.10 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.
1Trendnet
1Tew 929dru Firmware
Jun 17, 2026
Feb 28, 2025
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Trendnet TEW-929DRU 1.0.0.10 contains a Stored Cross-site Scripting (XSS) vulnerability via the The ssid key of wifi_data parameter on the /captive_portal.htm page.
1Trendnet
1Tew 929dru Firmware
Jun 17, 2026
Feb 28, 2025
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Trendnet TEW-929DRU 1.0.0.10 contains a Stored Cross-site Scripting (XSS) vulnerability via the configname parameter on the /cbi_addcert.htm page.
1Trendnet
1Teg 40128 Firmware
Jun 17, 2026
Feb 11, 2025
N/A· v4
5.9 MEDIUM· v3
N/A· v2
Buffer overflow vulnerability in Trendnet TEG-40128 Web Smart Switch v1(1.00.023) due to the lack of length verification, which is related to the mobile access point setup operation. The attacker can directly control the...Show more
Buffer overflow vulnerability in Trendnet TEG-40128 Web Smart Switch v1(1.00.023) due to the lack of length verification, which is related to the mobile access point setup operation. The attacker can directly control the remote target device by successfully exploiting this vulnerability.Show less
1Trendnet
1Tew 632brp Firmware
Jun 17, 2026
Jan 27, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TRENDnet TEW-632BRP v1.010B31 devices have an OS command injection vulnerability in the CGl interface "ntp_sync.cgi",which allows remote attackers to execute arbitrary commands via parameter "ntp_server" passed to the "n...Show more
TRENDnet TEW-632BRP v1.010B31 devices have an OS command injection vulnerability in the CGl interface "ntp_sync.cgi",which allows remote attackers to execute arbitrary commands via parameter "ntp_server" passed to the "ntp_sync.cgi" binary through a POST request.Show less