← Back

Trendnet

trendnet

190 CVEs • 129 products

Products (129)

Click to collapse
Toggle
Tew 812dru
tew-812dru
Tv Ip422w
tv-ip422w
Tv Ip422wn
tv-ip422wn
Tv Ip743sic
tv-ip743sic
Tew 731br
tew-731br
Tew 651br
tew-651br
Tew 652br
tew-652br
Tew 711br
tew-711br
Tew 810dr
tew-810dr
Tew 813dru
tew-813dru
Tew 823dru
tew-823dru
Tew 751dr
tew-751dr
Tew 752dru
tew-752dru
Tew733gr
tew733gr
Tew 673gru
tew-673gru
Tv Ip110wn
tv-ip110wn
Tv Ip121wn
tv-ip121wn
Tew 632brp
tew-632brp
Tew 827dru
tew-827dru
Tew 691gr
tew-691gr
Tew 692gr
tew-692gr
Tew 652brp
tew-652brp
Tew 652bru
tew-652bru
Ts S402
ts-s402
Tv Ip512wn
tv-ip512wn
Tw100 S4w1ca
tw100-s4w1ca
Tew 755ap
tew-755ap
Tew 755ap2kac
tew-755ap2kac
Tew 825dap
tew-825dap
Ti Pg1284i
ti-pg1284i
Ti G102i
ti-g102i
Ti G160i
ti-g160i
Ti G642i
ti-g642i
Ti Pg102i
ti-pg102i
Ti Pg541i
ti-pg541i

CVEs (190)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Trendnet
3Tew 651br Firmware
Tew 652brp FirmwareTew 652bru Firmware
Jun 17, 2026
Nov 11, 2024
N/A· v4
4.8 MEDIUM· v3
N/A· v2
TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS) vulnerability via the ptRule_ApplicationName_1.1.6.0.0 parameter on the /special_ap.htm page.
1Trendnet
3Tew 651br Firmware
Tew 652brp FirmwareTew 652bru Firmware
Jun 17, 2026
Nov 11, 2024
N/A· v4
4.8 MEDIUM· v3
N/A· v2
TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS) vulnerability via the macList_Name_1.1.1.0.0 parameter on the /filters.htm page.
1Trendnet
3Tew 651br Firmware
Tew 652brp FirmwareTew 652bru Firmware
Jun 17, 2026
Nov 11, 2024
N/A· v4
4.8 MEDIUM· v3
N/A· v2
TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS) vulnerability via the vsRule_VirtualServerName_1.1.10.0.0 parameter on the /virtual_server.htm page...Show more
TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS) vulnerability via the vsRule_VirtualServerName_1.1.10.0.0 parameter on the /virtual_server.htm page.Show less
1Trendnet
3Tew 651br Firmware
Tew 652brp FirmwareTew 652bru Firmware
Jun 17, 2026
Nov 11, 2024
N/A· v4
4.8 MEDIUM· v3
N/A· v2
TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS) vulnerability via the firewallRule_Name_1.1.1.0.0 parameter on the /firewall_setting.htm page.
1Trendnet
1Tew 820ap Firmware
Jun 17, 2026
Nov 11, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The boa httpd of Trendnet TEW-820AP 1.01.B01 has a stack overflow vulnerability in /boafrm/formIPv6Addr, /boafrm/formIpv6Setup, /boafrm/formDnsv6. The reason is that the check of ipv6 address is not sufficient, which all...Show more
The boa httpd of Trendnet TEW-820AP 1.01.B01 has a stack overflow vulnerability in /boafrm/formIPv6Addr, /boafrm/formIpv6Setup, /boafrm/formDnsv6. The reason is that the check of ipv6 address is not sufficient, which allows attackers to construct payloads for attacks.Show less
1Trendnet
1Tew 752dru Firmware
Jun 17, 2026
Aug 19, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In TRENDnet TEW-752DRU FW1.03B01, there is a buffer overflow vulnerability due to the lack of length verification for the service field in gena.cgi. Attackers who successfully exploit this vulnerability can cause the rem...Show more
In TRENDnet TEW-752DRU FW1.03B01, there is a buffer overflow vulnerability due to the lack of length verification for the service field in gena.cgi. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands.Show less
1Trendnet
1Tew 814dap Firmware
Jun 17, 2026
Jun 14, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a stack overflow vulnerability via the submit-url parameter at /formSysLog .
1Trendnet
1Tew 814dap Firmware
Jun 17, 2026
Jun 14, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a stack overflow vulnerability via the submit-url parameter at /formPasswordAuth .
1Trendnet
1Tew 814dap Firmware
Jun 17, 2026
Jun 14, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a command injection vulnerability via the ipv4_ping, ipv6_ping parameter at /formSystemCheck .
1Trendnet
1Tew 814dap Firmware
Jun 17, 2026
Jun 14, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a stack overflow via the submit-url parameter at /formNewSchedule
1Trendnet
1Tew 814dap Firmware
Jun 17, 2026
Jun 14, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in as root.
1Trendnet
1Tew 827dru Firmware
Jun 17, 2026
Jun 3, 2024
N/A· v4
6.3 MEDIUM· v3
N/A· v2
TRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows an authenticated user to execute arbitrary code by POSTing to apply.cgi via the action wizard_ipv6...Show more
TRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows an authenticated user to execute arbitrary code by POSTing to apply.cgi via the action wizard_ipv6 with a sufficiently long reboot_type key.Show less
1Trendnet
1Tew 827dru Firmware
Jun 17, 2026
Jun 3, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
TRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows an authenticated user to execute arbitrary code by POSTing to apply.cgi via the action vlan_setting...Show more
TRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows an authenticated user to execute arbitrary code by POSTing to apply.cgi via the action vlan_setting with a sufficiently long dns1 or dns 2 key.Show less
1Trendnet
1Tew 815dap Firmware
Jun 17, 2026
Apr 30, 2024
N/A· v4
6.4 MEDIUM· v3
N/A· v2
TRENDnet TEW-815DAP 1.0.2.0 is vulnerable to Command Injection via the do_setNTP function. An authenticated attacker with administrator privileges can leverage this vulnerability over the network via a malicious POST req...Show more
TRENDnet TEW-815DAP 1.0.2.0 is vulnerable to Command Injection via the do_setNTP function. An authenticated attacker with administrator privileges can leverage this vulnerability over the network via a malicious POST request.Show less
1Trendnet
1Tew 821dap Firmware
Jun 17, 2026
Mar 26, 2024
N/A· v4
8.0 HIGH· v3
N/A· v2
Buffer Overflow vulnerability in TRENDnet Trendnet AC1200 TEW-821DAP with firmware version 3.00b06 allows an attacker to execute arbitrary code via the adm_mod_pwd action.
1Trendnet
1Tew 821dap Firmware
Jun 17, 2026
Mar 26, 2024
N/A· v4
8.0 HIGH· v3
N/A· v2
Buffer Overflow vulnerability in TRENDnet AC1200 TEW-821DAP with firmware version 3.00b06 allows an attacker to execute arbitrary code via the adm_add_user action.
1Trendnet
1Tew 821dap Firmware
Jul 9, 2026
Mar 26, 2024
N/A· v4
8.0 HIGH· v3
N/A· v2
An issue in TRENDnet Trendnet AC1200 Dual Band PoE Indoor Wireless Access Point TEW-821DAP v.3.00b06 allows an attacker to execute arbitrary code via the 'mycli' command-line interface component.
1Trendnet
1Tew 827dru Firmware
Jun 17, 2026
Mar 15, 2024
N/A· v4
10.0 CRITICAL· v3
N/A· v2
There is a command injection vulnerability in the TRENDnet TEW-827DRU router with firmware version 2.10B01. An attacker can inject commands into the post request parameters usapps.@smb[%d].username in the apply.cgi inter...Show more
There is a command injection vulnerability in the TRENDnet TEW-827DRU router with firmware version 2.10B01. An attacker can inject commands into the post request parameters usapps.@smb[%d].username in the apply.cgi interface, thereby gaining root shell privileges.Show less
1Trendnet
1Tew 827dru Firmware
Jun 17, 2026
Mar 15, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
There is a command injection vulnerability in the TRENDnet TEW-827DRU router with firmware version 2.10B01. An attacker can inject commands into the post request parameters usapps.config.smb_admin_name in the apply.cgi i...Show more
There is a command injection vulnerability in the TRENDnet TEW-827DRU router with firmware version 2.10B01. An attacker can inject commands into the post request parameters usapps.config.smb_admin_name in the apply.cgi interface, thereby gaining root shell privileges.Show less
1Trendnet
1Tew 822dre Firmware
Jun 17, 2026
Feb 29, 2024
N/A· v4
6.8 MEDIUM· v3
N/A· v2
An issue in TRENDnet TEW-822DRE v.1.03B02 allows a local attacker to execute arbitrary code via the parameters ipv4_ping in the /boafrm/formSystemCheck.