MidnightBSD

Advisories for trendnet

CVE-2012-4876 HIGH

Stack-based buffer overflow in the UltraMJCam ActiveX Control in TRENDnet SecurView TV-IP121WN Wireless Internet Camera allows remote attackers to execute arbitrary code via a long string to the OpenFileDlg method.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
trendnet securview_wireless_internet_camera tv-ip121wn
trendnet securview_wireless_internet_camera_activex_control 1.1.52.18
CVE-2013-3098 MEDIUM

Multiple cross-site request forgery (CSRF) vulnerabilities in TRENDnet TEW-812DRU router with firmware before 1.0.9.0 allow remote attackers to hijack the authentication of administrators for requests that (1) change admin credentials in a request to setSysAdm.cgi, (2) enable remote management or (3) enable port forwarding in an Apply action to uapply.cgi, or (4) have unspecified impact via a request to setNTP.cgi. NOTE: some of these details are obtained from third party information.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
trendnet tew-812dru_firmware 1.0.8.0
trendnet tew-812dru -
CVE-2013-3365 HIGH

TRENDnet TEW-812DRU router allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) wan network prefix to internet/ipv6.asp; (2) remote port to adm/management.asp; (3) pptp username, (4) pptp password, (5) ip, (6) gateway, (7) l2tp username, or (8) l2tp password to internet/wan.asp; (9) NtpDstStart, (10) NtpDstEnd, or (11) NtpDstOffset to adm/time.asp; or (12) device url to adm/management.asp. NOTE: vectors 9, 10, and 11 can be exploited by unauthenticated remote attackers by leveraging CVE-2013-3098.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-78,

Products Affected

Vendor Product Version
trendnet tew-812dru -
CVE-2013-4659 HIGH

Buffer overflow in Broadcom ACSD allows remote attackers to execute arbitrary code via a long string to TCP port 5916. This component is used on routers of multiple vendors including ASUS RT-AC66U and TRENDnet TEW-812DRU.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
asus rt-ac66u_firmware -
trendnet tew-812dru_firmware -
CVE-2014-10011 HIGH

Stack-based buffer overflow in UltraCamLib in the UltraCam ActiveX Control (UltraCamX.ocx) for the TRENDnet SecurView camera TV-IP422WN allows remote attackers to execute arbitrary code via a long string to the (1) CGI_ParamSet, (2) OpenFileDlg, (3) SnapFileName, (4) Password, (5) SetCGIAPNAME, (6) AccountCode, or (7) RemoteHost function.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
trendnet tv-ip422w -
trendnet tv-ip422wn -
CVE-2014-8579 HIGH

TRENDnet TEW-823DRU devices with firmware before 1.00b36 have a hardcoded password of kcodeskcodes for the root account, which makes it easier for remote attackers to obtain access via an FTP session.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-798,

Products Affected

Vendor Product Version
trendnet tew-823dru_firmware *
CVE-2015-1187 HIGH

The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ccp.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9

CVSS 2.0

Severity: HIGH

Problem Type: CWE-287,CWE-287,

Products Affected

Vendor Product Version
trendnet tew-651br_firmware -
dlink dir-636l_firmware 1.04
dlink dir-826l_firmware 1.00
dlink dir-820l_firmware 1.02
dlink dir-830l_firmware 1.00
trendnet tew-731br_firmware 2.01
trendnet tew-711br_firmware 1.00
dlink dir-808l_firmware 1.03
dlink dir-820l_firmware 2.01
trendnet tew-652br_firmware -
trendnet tew-810dr_firmware 1.00
trendnet tew-813dru_firmware 1.00
dlink dir-626l_firmware 1.04
dlink dir-810l_firmware 1.01
dlink dir-820l_firmware 1.05
dlink dir-836l_firmware 1.01
dlink dir-810l_firmware 2.02
dlink dir-651_firmware 1.10na
CVE-2015-2880 HIGH

TRENDnet WiFi Baby Cam TV-IP743SIC has a password of admin for the backdoor root account.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-287,

Products Affected

Vendor Product Version
trendnet tv-ip743sic -
CVE-2018-19239 HIGH

TRENDnet TEW-673GRU v1.00b40 devices have an OS command injection vulnerability in the start_arpping function of the timer binary, which allows remote attackers to execute arbitrary commands via three parameters (dhcpd_start, dhcpd_end, and lan_ipaddr) passed to the apply.cgi binary through a POST request.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-78,

Products Affected

Vendor Product Version
trendnet tew-673gru_firmware 1.00b40
CVE-2018-19240 HIGH

Buffer overflow in network.cgi on TRENDnet TV-IP110WN V1.2.2 build 68, V1.2.2.65, and V1.2.2 build 64 and TV-IP121WN V1.2.2 build 28 devices allows attackers to hijack the control flow to any attacker-specified location by crafting a POST request payload (without authentication).

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
trendnet tv-ip110wn_firmware 1.2.2.65
trendnet tv-ip121wn_firmware 1.2.2.28
trendnet tv-ip110wn_firmware 1.2.2.68
trendnet tv-ip110wn_firmware 1.2.2.64
CVE-2018-19241 MEDIUM

Buffer overflow in video.cgi on TRENDnet TV-IP110WN V1.2.2 build 68, V1.2.2.65, and V1.2.2 build 64 and TV-IP121WN V1.2.2 build 28 devices allows attackers to hijack the control flow to any attacker-specified location by crafting a POST request payload (without authentication).

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
trendnet tv-ip110wn_firmware 1.2.2.65
trendnet tv-ip121wn_firmware 1.2.2.28
trendnet tv-ip110wn_firmware 1.2.2.68
trendnet tv-ip110wn_firmware 1.2.2.64
CVE-2018-19242 MEDIUM

Buffer overflow in apply.cgi on TRENDnet TEW-632BRP 1.010B32 and TEW-673GRU devices allows attackers to hijack the control flow to any attacker-specified location by crafting a POST request payload (with authentication).

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
trendnet tew-673gru_firmware 1.00b40
trendnet tew-632brp_firmware 1.010b32
CVE-2018-7034 MEDIUM

TRENDnet TEW-751DR v1.03B03, TEW-752DRU v1.03B01, and TEW733GR v1.03B01 devices allow authentication bypass via an AUTHORIZED_GROUP=1 value, as demonstrated by a request for getcfg.php.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
trendnet tew-752dru_firmware 1.03b01
trendnet tew733gr_firmware 1.03b01
trendnet tew-751dr_firmware 1.03b03
CVE-2019-11417 HIGH

system.cgi on TRENDnet TV-IP110WN cameras has a buffer overflow caused by an inadequate source-length check before a strcpy operation in the respondAsp function. Attackers can exploit the vulnerability by using the languse parameter with a long string. This affects 1.2.2 build 28, 64, 65, and 68.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-20,CWE-787,

Products Affected

Vendor Product Version
trendnet tv-ip110wn_firmware 1.2.2.65
trendnet tv-ip110wn_firmware 1.2.2.28
trendnet tv-ip110wn_firmware 1.2.2.68
trendnet tv-ip110wn_firmware 1.2.2.64
CVE-2019-11418 HIGH

apply.cgi on the TRENDnet TEW-632BRP 1.010B32 router has a buffer overflow via long strings to the SOAPACTION:HNAP1 interface.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
trendnet tew-632brp_firmware 1.010b32