CVE-2025-65202
PoC —CVSS 3.1
8.0 high
EPSS
7%p94
Published
()
Modified
Description
TRENDnet TEW-657BRM 1.00.1 has an authenticated remote OS command injection vulnerability in the setup.cgi binary, exploitable via the HTTP parameters "command", "todo", and "next_file," which allows an attacker to execute arbitrary commands with root privileges.
- Vendors
- trendnet
- Products
- tew-657brm firmware
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.