Vulnerabilities (CVE)

Filtered by vendor Trendnet Subscribe
Total 130 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-51833 1 Trendnet 2 Tew-411brpplus, Tew-411brpplus Firmware 2024-01-31 N/A 8.1 HIGH
A command injection issue in TRENDnet TEW-411BRPplus v.2.07_eu that allows a local attacker to execute arbitrary code via the data1 parameter in the debug.cgi page.
CVE-2023-49237 1 Trendnet 2 Tv-ip1314pi, Tv-ip1314pi Firmware 2024-01-16 N/A 9.8 CRITICAL
An issue was discovered on TRENDnet TV-IP1314PI 5.5.3 200714 devices. Command injection can occur because the system function is used by davinci to unpack language packs without strict filtering of URL strings.
CVE-2023-49236 1 Trendnet 2 Tv-ip1314pi, Tv-ip1314pi Firmware 2024-01-12 N/A 9.8 CRITICAL
A stack-based buffer overflow was discovered on TRENDnet TV-IP1314PI 5.5.3 200714 devices, leading to arbitrary command execution. This occurs because of lack of length validation during an sscanf of a user-entered scale field in the RTSP playback function of davinci.
CVE-2023-49235 1 Trendnet 2 Tv-ip1314pi, Tv-ip1314pi Firmware 2024-01-12 N/A 9.8 CRITICAL
An issue was discovered in libremote_dbg.so on TRENDnet TV-IP1314PI 5.5.3 200714 devices. Filtering of debug information is mishandled during use of popen. Consequently, an attacker can bypass validation and execute a shell command.
CVE-2022-46597 1 Trendnet 2 Tew-755ap, Tew-755ap Firmware 2023-12-10 N/A 9.8 CRITICAL
TRENDnet TEW755AP 1.13B01 was discovered to contain a command injection vulnerability via the sys_service parameter in the setup_wizard_mydlink (sub_4104B8) function.
CVE-2022-46582 1 Trendnet 2 Tew-755ap, Tew-755ap Firmware 2023-12-10 N/A 9.8 CRITICAL
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the login_name parameter in the do_graph_auth (sub_4061E0) function.
CVE-2022-46580 1 Trendnet 2 Tew-755ap, Tew-755ap Firmware 2023-12-10 N/A 9.8 CRITICAL
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the user_edit_page parameter in the wifi_captive_portal function.
CVE-2022-44373 1 Trendnet 2 Tew-820ap, Tew-820ap Firmware 2023-12-10 N/A 8.8 HIGH
A stack overflow vulnerability exists in TrendNet Wireless AC Easy-Upgrader TEW-820AP (Version v1.0R, firmware version 1.01.B01) which may result in remote code execution.
CVE-2022-46589 1 Trendnet 2 Tew-755ap, Tew-755ap Firmware 2023-12-10 N/A 9.8 CRITICAL
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the cameo.cameo.netstat_option parameter in the tools_netstat (sub_41E730) function.
CVE-2022-46584 1 Trendnet 2 Tew-755ap, Tew-755ap Firmware 2023-12-10 N/A 9.8 CRITICAL
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the qcawifi.wifi%d_vap%d.maclist parameter in the kick_ban_wifi_mac_deny (sub_415D7C) function.
CVE-2023-23120 1 Trendnet 2 Tv-ip651wi, Tv-ip651wi Firmware 2023-12-10 N/A 5.9 MEDIUM
The use of the cyclic redundancy check (CRC) algorithm for integrity check during firmware update makes TRENDnet TV-IP651WI Network Camera firmware version v1.07.01 and earlier vulnerable to firmware modification attacks. An attacker can conduct a man-in-the-middle (MITM) attack to modify the new firmware image and bypass the checksum verification.
CVE-2022-46594 1 Trendnet 2 Tew-755ap, Tew-755ap Firmware 2023-12-10 N/A 9.8 CRITICAL
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the update_file_name parameter in the auto_up_fw (sub_420A04) function.
CVE-2022-46591 1 Trendnet 2 Tew-755ap, Tew-755ap Firmware 2023-12-10 N/A 9.8 CRITICAL
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the reject_url parameter in the reject (sub_41BD60) function.
CVE-2022-46590 1 Trendnet 2 Tew-755ap, Tew-755ap Firmware 2023-12-10 N/A 9.8 CRITICAL
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the cameo.cameo.netstat_rsname parameter in the tools_netstat (sub_41E730) function.
CVE-2022-46583 1 Trendnet 2 Tew-755ap, Tew-755ap Firmware 2023-12-10 N/A 9.8 CRITICAL
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the reboot_type parameter in the wizard_ipv6 (sub_41C380) function.
CVE-2022-46599 1 Trendnet 2 Tew-755ap, Tew-755ap Firmware 2023-12-10 N/A 9.8 CRITICAL
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the setlogo_num parameter in the icp_setlogo_img (sub_41DBF4) function.
CVE-2022-46601 1 Trendnet 2 Tew-755ap, Tew-755ap Firmware 2023-12-10 N/A 9.8 CRITICAL
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the setbg_num parameter in the icp_setbg_img (sub_41DD68) function.
CVE-2022-46585 1 Trendnet 2 Tew-755ap, Tew-755ap Firmware 2023-12-10 N/A 9.8 CRITICAL
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the REMOTE_USER parameter in the get_access (sub_45AC2C) function.
CVE-2022-46588 1 Trendnet 2 Tew-755ap, Tew-755ap Firmware 2023-12-10 N/A 9.8 CRITICAL
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the sys_service parameter in the setup_wizard_mydlink (sub_4104B8) function.
CVE-2022-46592 1 Trendnet 2 Tew-755ap, Tew-755ap Firmware 2023-12-10 N/A 9.8 CRITICAL
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the wps_sta_enrollee_pin parameter in the set_sta_enrollee_pin_5g function.