ZeroHour

CVE-2025-15472

PoC moderate

Authenticated Command Injection RCE in TRENDnet TEW-811DRU Router

CVSS 4.0
7.3 high
EPSS
23%p98
Published
()
Modified
AI analysis

CVE-2025-15472 is an operating system command injection flaw in the httpd service of the TRENDnet TEW-811DRU router, located in the setDeviceURL function reached through the uapply.cgi endpoint. An attacker triggers it by submitting a crafted DeviceURL parameter to the router's web interface, and per the CVSS 4.0 vector (PR:H) the attack requires privileges at the administrator level, so it presumes valid access to the management interface. Successful exploitation yields remote command execution on the device with high impact to confidentiality, integrity, and availability, effectively giving the attacker control of the router. Only firmware version 1.0.2.0 is named in the disclosure, the vendor was contacted early but did not respond, and no fixed release is documented. A public proof of concept exists, the EPSS score of 22.6% (98th percentile) indicates a meaningful likelihood of exploitation within 30 days, but the flaw is not in CISA KEV and no confirmed in-the-wild exploitation is reported.

What to do: Because the vendor reportedly did not respond and no fixed firmware is documented, owners should verify their TEW-811DRU firmware version and ensure the router's web management interface is not reachable from the WAN (disable remote administration). If remote management is required, restrict access to trusted source addresses or tunnel it via VPN, and monitor TRENDnet support channels for an updated firmware release. Review the published proof of concept to confirm whether the DeviceURL handling in uapply.cgi is reachable in your deployment.

Affected
TRENDnet TEW-811DRU firmware1.0.2.0 (version cited in the disclosure; whether other versions are affected is not specified)
Estimated exposure
moderateon the order of 1,000–10,000 internet-exposed devices (estimate; no public install-base figures available) — No public active-install or scan counts exist for this older consumer router model, so the estimate assumes only a small fraction of deployed TEW-811DRU units expose their web management interface to the internet, consistent with typical…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A flaw has been found in TRENDnet TEW-811DRU 1.0.2.0. This affects the function setDeviceURL of the file uapply.cgi of the component httpd . This manipulation of the argument DeviceURL causes os command injection. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Vendors
trendnet
Products
tew-811dru firmware
Weakness
CWE-77, CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.