ZeroHour

Vulnerabilities

180 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-10063
+4 in the same advisory: …10062 …10061 …10060 …10064
A vulnerability was identified in TRENDnet TEW-432BRP 3.10B20.

A vulnerability was identified in TRENDnet TEW-432BRP 3.10B20. Affected by this issue is the function formWPS of the file /goform/formWPS. Such manipulation of the argument peerPin leads to stack-based buffer overflow. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities." This vulnerability only affects products that are no longer supported by the maintainer.

NVD description · AI analysis pending
7.4
group max
<1% PoC
  • trendnet tew-432brp firmware
CVE-2026-7607
A security vulnerability has been detected in TRENDnet TEW-821DAP 1.12B01.

A security vulnerability has been detected in TRENDnet TEW-821DAP 1.12B01. Impacted is the function auto_update_firmware of the component Firmware Udpate. The manipulation of the argument str leads to buffer overflow. The attack may be initiated remotely. The vendor explains: "That firmware version will only work on our hardware version v1.xR. We have already EOL that product 8 years ago and are no longer selling". This vulnerability only affects products that are no longer supported by the maintainer.

NVD description · AI analysis pending
8.7
group max
<1% PoC
  • trendnet tew-821dap firmware
CVE-2026-5350
A security flaw has been discovered in Trendnet TEW-657BRM 1.00.1.

A security flaw has been discovered in Trendnet TEW-657BRM 1.00.1. The impacted element is the function update_pcdb of the file /setup.cgi. The manipulation of the argument mac_pc_dba results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor confirms, that "[t]he product in question (...) has been discontinued and end of life since June 23, 2011, that is more than 14 years ago. We no longer provide support for this product, so we are not able to confirm the vulnerabilities. We will make an announcement on our website's product support page and notify customers who registered their products with us." This vulnerability only affects products that are no longer supported by the maintainer.

NVD description · AI analysis pending
7.4
group max
<1% PoC
  • trendnet tew-657brm firmware
CVE-2026-5184
+1 in the same advisory: …5183
A vulnerability was identified in TRENDnet TEW-713RE up to 1.02.

A vulnerability was identified in TRENDnet TEW-713RE up to 1.02. The impacted element is an unknown function of the file /goform/setSysAdm. The manipulation of the argument admuser leads to command injection. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
2.19% PoC
  • trendnet tew-713re firmware
CVE-2025-15472
Authenticated Command Injection RCE in TRENDnet TEW-811DRU Router

CVE-2025-15472 is an operating system command injection flaw in the httpd service of the TRENDnet TEW-811DRU router, located in the setDeviceURL function reached through the uapply.cgi endpoint. An attacker triggers it by submitting a crafted DeviceURL parameter to the router's web interface, and per the CVSS 4.0 vector (PR:H) the attack requires privileges at the administrator level, so it presumes valid access to the management interface. Successful exploitation yields remote command execution on the device with high impact to confidentiality, integrity, and availability, effectively giving the attacker control of the router. Only firmware version 1.0.2.0 is named in the disclosure, the vendor was contacted early but did not respond, and no fixed release is documented. A public proof of concept exists, the EPSS score of 22.6% (98th percentile) indicates a meaningful likelihood of exploitation within 30 days, but the flaw is not in CISA KEV and no confirmed in-the-wild exploitation is reported.

Do: Because the vendor reportedly did not respond and no fixed firmware is documented, owners should verify their TEW-811DRU firmware version and ensure the router's web management interface is not reachable from the WAN (disable remote administration). If remote management is required, restrict access to trusted source addresses or tunnel it via VPN, and monitor TRENDnet support channels for an updated firmware release. Review the published proof of concept to confirm whether the DeviceURL handling in uapply.cgi is reachable in your deployment.

7.323% PoC
  • TRENDnet TEW-811DRU firmware 1.0.2.0 (version cited in the disclosure; whether other versions are affected is not specified)
moderateon the order of 1,000–10,000 internet-exposed devices (estimate; no public install-base figures available)
CVE-2025-15471
A vulnerability was detected in TRENDnet TEW-713RE 1.02.

A vulnerability was detected in TRENDnet TEW-713RE 1.02. The impacted element is an unknown function of the file /goformX/formFSrvX. The manipulation of the argument SZCMD results in os command injection. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor confirms: "The product in question TEW-731RE for CVE-2025-15471 has been discontinued and end of life since October 23, 2020. We no longer provide support for this product, so we are not able to confirm the vulnerabilities. We will make an announcement on the website product support page and notify customers who registered their products with us." This vulnerability only affects products that are no longer supported by the maintainer.

NVD description · AI analysis pending
8.914% PoC
  • trendnet tew-713re firmware
CVE-2025-15139
A vulnerability has been found in TRENDnet TEW-822DRE 1.00B21/1.01B06.

A vulnerability has been found in TRENDnet TEW-822DRE 1.00B21/1.01B06. This affects the function sub_43ACF4 of the file /boafrm/formWsc. Such manipulation of the argument peerPin leads to command injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
2.113% PoC
  • trendnet tew-822dre firmware
CVE-2025-15137
+1 in the same advisory: …15136
A vulnerability was detected in TRENDnet TEW-800MB 1.0.1.0.

A vulnerability was detected in TRENDnet TEW-800MB 1.0.1.0. Affected by this vulnerability is the function sub_F934 of the file NTPSyncWithHost.cgi. The manipulation results in command injection. The attack may be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
7.411% PoC
  • trendnet tew-800mb firmware
CVE-2025-65202
TRENDnet TEW-657BRM 1.00.1 has an authenticated remote OS command injection vulnerability in the setup.cgi binary, exploitable via the HTTP parameters "command"

TRENDnet TEW-657BRM 1.00.1 has an authenticated remote OS command injection vulnerability in the setup.cgi binary, exploitable via the HTTP parameters "command", "todo", and "next_file," which allows an attacker to execute arbitrary commands with root privileges.

NVD description · AI analysis pending
8.07% PoC
  • trendnet tew-657brm firmware
CVE-2024-46484
TRENDnet TV-IP410 vA1.0R was discovered to contain an OS command injection vulnerability via the /server/cgi-bin/testserv.cgi component.

TRENDnet TV-IP410 vA1.0R was discovered to contain an OS command injection vulnerability via the /server/cgi-bin/testserv.cgi component.

NVD description · AI analysis pending
9.81%
  • trendnet tv-ip410 firmware
CVE-2025-8759
A vulnerability was found in TRENDnet TN-200 1.02b02.

A vulnerability was found in TRENDnet TN-200 1.02b02. It has been declared as problematic. This vulnerability affects unknown code of the component Lighttpd. The manipulation of the argument secdownload.secret with the input neV3rUseMe leads to use of hard-coded cryptographic key . The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
2.9<1%
  • trendnet tn-200 firmware
CVE-2025-44649
+1 in the same advisory: …44647
In the configuration file of racoon in the TRENDnet TEW-WLC100P 2.03b03, the first item of exchage_mode is set to aggressive.

In the configuration file of racoon in the TRENDnet TEW-WLC100P 2.03b03, the first item of exchage_mode is set to aggressive. Aggressive mode in IKE Phase 1 exposes identity information in plaintext, is vulnerable to offline dictionary attacks, and lacks flexibility in negotiating security parameters.

NVD description · AI analysis pending
7.5
group max
<1%
  • trendnet tew-wlc100p firmware
CVE-2025-44651
In TRENDnet TPL-430AP FW1.0, the USERLIMIT_GLOBAL option is set to 0 in the bftpd-related configuration file.

In TRENDnet TPL-430AP FW1.0, the USERLIMIT_GLOBAL option is set to 0 in the bftpd-related configuration file. This can cause DoS attacks when unlimited users are connected.

NVD description · AI analysis pending
7.5<1%
  • trendnet tpl-430ap firmware
CVE-2025-2960
A vulnerability classified as problematic has been found in TRENDnet TEW-637AP and TEW-638APB 1.2.7/1.3.0.106.

A vulnerability classified as problematic has been found in TRENDnet TEW-637AP and TEW-638APB 1.2.7/1.3.0.106. This affects the function sub_41DED0 of the file /bin/goahead of the component HTTP Request Handler. The manipulation leads to null pointer dereference. Access to the local network is required for this attack. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
7.1<1% PoC ×2
  • trendnet tew-637ap firmware
  • trendnet tew-638apb firmware
CVE-2025-2959
A vulnerability was found in TRENDnet TEW-410APB 1.3.06b.

A vulnerability was found in TRENDnet TEW-410APB 1.3.06b. It has been rated as problematic. Affected by this issue is the function sub_4019A0 of the file /usr/sbin/httpd of the component HTTP Request Handler. The manipulation leads to null pointer dereference. The attack needs to be initiated within the local network. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
7.1<1% PoC ×2
  • trendnet tew-410apb firmware
CVE-2025-2958
A vulnerability was found in TRENDnet TEW-818DRU 1.0.14.6.

A vulnerability was found in TRENDnet TEW-818DRU 1.0.14.6. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /usr/sbin/httpd of the component HTTP Request Handler. The manipulation leads to denial of service. The attack needs to be done within the local network. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
7.1<1% PoC ×2
  • trendnet tew-818dru firmware
CVE-2025-25428
+3 in the same advisory: …25429 …25431 …25430
TRENDnet TEW-929DRU 1.0.0.10 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.

TRENDnet TEW-929DRU 1.0.0.10 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.

NVD description · AI analysis pending
8.0
group max
<1% PoC
  • trendnet tew-929dru firmware
CVE-2025-25523
Buffer overflow vulnerability in Trendnet TEG-40128 Web Smart Switch v1(1.00.023) due to the lack of length verification, which is related to the mobile access

Buffer overflow vulnerability in Trendnet TEG-40128 Web Smart Switch v1(1.00.023) due to the lack of length verification, which is related to the mobile access point setup operation. The attacker can directly control the remote target device by successfully exploiting this vulnerability.

NVD description · AI analysis pending
5.9<1%
  • trendnet teg-40128 firmware
CVE-2024-57590
TRENDnet TEW-632BRP v1.010B31 devices have an OS command injection vulnerability in the CGl interface "ntp_sync.cgi",which allows remote attackers to execute ar

TRENDnet TEW-632BRP v1.010B31 devices have an OS command injection vulnerability in the CGl interface "ntp_sync.cgi",which allows remote attackers to execute arbitrary commands via parameter "ntp_server" passed to the "ntp_sync.cgi" binary through a POST request.

NVD description · AI analysis pending
9.81%
  • trendnet tew-632brp firmware
CVE-2024-51190
+3 in the same advisory: …51189 …51188 …51187
TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS) vulnerability via the ptRule_Applicatio

TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS) vulnerability via the ptRule_ApplicationName_1.1.6.0.0 parameter on the /special_ap.htm page.

NVD description · AI analysis pending
4.8<1% PoC
  • trendnet tew-651br firmware
  • trendnet tew-652brp firmware
  • trendnet tew-652bru firmware
CVE-2024-50667
The boa httpd of Trendnet TEW-820AP 1.01.B01 has a stack overflow vulnerability in /boafrm/formIPv6Addr, /boafrm/formIpv6Setup, /boafrm/formDnsv6.

The boa httpd of Trendnet TEW-820AP 1.01.B01 has a stack overflow vulnerability in /boafrm/formIPv6Addr, /boafrm/formIpv6Setup, /boafrm/formDnsv6. The reason is that the check of ipv6 address is not sufficient, which allows attackers to construct payloads for attacks.

NVD description · AI analysis pending
9.87% PoC
  • trendnet tew-820ap firmware
CVE-2024-42813
In TRENDnet TEW-752DRU FW1.03B01, there is a buffer overflow vulnerability due to the lack of length verification for the service field in gena.cgi.

In TRENDnet TEW-752DRU FW1.03B01, there is a buffer overflow vulnerability due to the lack of length verification for the service field in gena.cgi. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands.

NVD description · AI analysis pending
9.8<1% PoC
  • trendnet tew-752dru firmware
CVE-2024-37642
+3 in the same advisory: …37643 …37645 …37641
TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a command injection vulnerability via the ipv4_ping, ipv6_ping parameter at /formSystemCheck .

TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a command injection vulnerability via the ipv4_ping, ipv6_ping parameter at /formSystemCheck .

NVD description · AI analysis pending
9.1
group max
11% PoC
  • trendnet tew-814dap firmware