CVE-2025-15472
PoC moderateAuthenticated Command Injection RCE in TRENDnet TEW-811DRU Router
CVE-2025-15472 is an operating system command injection flaw in the httpd service of the TRENDnet TEW-811DRU router, located in the setDeviceURL function reached through the uapply.cgi endpoint. An attacker triggers it by submitting a crafted DeviceURL parameter to the router's web interface, and per the CVSS 4.0 vector (PR:H) the attack requires privileges at the administrator level, so it presumes valid access to the management interface. Successful exploitation yields remote command execution on the device with high impact to confidentiality, integrity, and availability, effectively giving the attacker control of the router. Only firmware version 1.0.2.0 is named in the disclosure, the vendor was contacted early but did not respond, and no fixed release is documented. A public proof of concept exists, the EPSS score of 22.6% (98th percentile) indicates a meaningful likelihood of exploitation within 30 days, but the flaw is not in CISA KEV and no confirmed in-the-wild exploitation is reported.
What to do: Because the vendor reportedly did not respond and no fixed firmware is documented, owners should verify their TEW-811DRU firmware version and ensure the router's web management interface is not reachable from the WAN (disable remote administration). If remote management is required, restrict access to trusted source addresses or tunnel it via VPN, and monitor TRENDnet support channels for an updated firmware release. Review the published proof of concept to confirm whether the DeviceURL handling in uapply.cgi is reachable in your deployment.
| TRENDnet TEW-811DRU firmware | 1.0.2.0 (version cited in the disclosure; whether other versions are affected is not specified) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A flaw has been found in TRENDnet TEW-811DRU 1.0.2.0. This affects the function setDeviceURL of the file uapply.cgi of the component httpd . This manipulation of the argument DeviceURL causes os command injection. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
- Vendors
- trendnet
- Products
- tew-811dru firmware
- Weakness
- CWE-77, CWE-78
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.