Stack-based buffer overflow in the UltraMJCam ActiveX Control in TRENDnet SecurView TV-IP121WN Wireless Internet Camera allows remote attackers to execute arbitrary code via a long string to the OpenFileDlg method.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| trendnet | securview_wireless_internet_camera | tv-ip121wn |
| trendnet | securview_wireless_internet_camera_activex_control | 1.1.52.18 |
Multiple cross-site request forgery (CSRF) vulnerabilities in TRENDnet TEW-812DRU router with firmware before 1.0.9.0 allow remote attackers to hijack the authentication of administrators for requests that (1) change admin credentials in a request to setSysAdm.cgi, (2) enable remote management or (3) enable port forwarding in an Apply action to uapply.cgi, or (4) have unspecified impact via a request to setNTP.cgi. NOTE: some of these details are obtained from third party information.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| trendnet | tew-812dru_firmware | 1.0.8.0 |
| trendnet | tew-812dru | - |
TRENDnet TEW-812DRU router allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) wan network prefix to internet/ipv6.asp; (2) remote port to adm/management.asp; (3) pptp username, (4) pptp password, (5) ip, (6) gateway, (7) l2tp username, or (8) l2tp password to internet/wan.asp; (9) NtpDstStart, (10) NtpDstEnd, or (11) NtpDstOffset to adm/time.asp; or (12) device url to adm/management.asp. NOTE: vectors 9, 10, and 11 can be exploited by unauthenticated remote attackers by leveraging CVE-2013-3098.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| trendnet | tew-812dru | - |
Buffer overflow in Broadcom ACSD allows remote attackers to execute arbitrary code via a long string to TCP port 5916. This component is used on routers of multiple vendors including ASUS RT-AC66U and TRENDnet TEW-812DRU.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| asus | rt-ac66u_firmware | - |
| trendnet | tew-812dru_firmware | - |
Stack-based buffer overflow in UltraCamLib in the UltraCam ActiveX Control (UltraCamX.ocx) for the TRENDnet SecurView camera TV-IP422WN allows remote attackers to execute arbitrary code via a long string to the (1) CGI_ParamSet, (2) OpenFileDlg, (3) SnapFileName, (4) Password, (5) SetCGIAPNAME, (6) AccountCode, or (7) RemoteHost function.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| trendnet | tv-ip422w | - |
| trendnet | tv-ip422wn | - |
TRENDnet TEW-823DRU devices with firmware before 1.00b36 have a hardcoded password of kcodeskcodes for the root account, which makes it easier for remote attackers to obtain access via an FTP session.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-798,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| trendnet | tew-823dru_firmware | * |
The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ccp.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 3.9 | 5.9 |
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 3.9 | 5.9 |
CVSS 2.0
Severity: HIGH
Problem Type: CWE-287,CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| trendnet | tew-651br_firmware | - |
| dlink | dir-636l_firmware | 1.04 |
| dlink | dir-826l_firmware | 1.00 |
| dlink | dir-820l_firmware | 1.02 |
| dlink | dir-830l_firmware | 1.00 |
| trendnet | tew-731br_firmware | 2.01 |
| trendnet | tew-711br_firmware | 1.00 |
| dlink | dir-808l_firmware | 1.03 |
| dlink | dir-820l_firmware | 2.01 |
| trendnet | tew-652br_firmware | - |
| trendnet | tew-810dr_firmware | 1.00 |
| trendnet | tew-813dru_firmware | 1.00 |
| dlink | dir-626l_firmware | 1.04 |
| dlink | dir-810l_firmware | 1.01 |
| dlink | dir-820l_firmware | 1.05 |
| dlink | dir-836l_firmware | 1.01 |
| dlink | dir-810l_firmware | 2.02 |
| dlink | dir-651_firmware | 1.10na |
TRENDnet WiFi Baby Cam TV-IP743SIC has a password of admin for the backdoor root account.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| trendnet | tv-ip743sic | - |
TRENDnet TEW-673GRU v1.00b40 devices have an OS command injection vulnerability in the start_arpping function of the timer binary, which allows remote attackers to execute arbitrary commands via three parameters (dhcpd_start, dhcpd_end, and lan_ipaddr) passed to the apply.cgi binary through a POST request.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| trendnet | tew-673gru_firmware | 1.00b40 |
Buffer overflow in network.cgi on TRENDnet TV-IP110WN V1.2.2 build 68, V1.2.2.65, and V1.2.2 build 64 and TV-IP121WN V1.2.2 build 28 devices allows attackers to hijack the control flow to any attacker-specified location by crafting a POST request payload (without authentication).
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| trendnet | tv-ip110wn_firmware | 1.2.2.65 |
| trendnet | tv-ip121wn_firmware | 1.2.2.28 |
| trendnet | tv-ip110wn_firmware | 1.2.2.68 |
| trendnet | tv-ip110wn_firmware | 1.2.2.64 |
Buffer overflow in video.cgi on TRENDnet TV-IP110WN V1.2.2 build 68, V1.2.2.65, and V1.2.2 build 64 and TV-IP121WN V1.2.2 build 28 devices allows attackers to hijack the control flow to any attacker-specified location by crafting a POST request payload (without authentication).
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| trendnet | tv-ip110wn_firmware | 1.2.2.65 |
| trendnet | tv-ip121wn_firmware | 1.2.2.28 |
| trendnet | tv-ip110wn_firmware | 1.2.2.68 |
| trendnet | tv-ip110wn_firmware | 1.2.2.64 |
Buffer overflow in apply.cgi on TRENDnet TEW-632BRP 1.010B32 and TEW-673GRU devices allows attackers to hijack the control flow to any attacker-specified location by crafting a POST request payload (with authentication).
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| trendnet | tew-673gru_firmware | 1.00b40 |
| trendnet | tew-632brp_firmware | 1.010b32 |
TRENDnet TEW-751DR v1.03B03, TEW-752DRU v1.03B01, and TEW733GR v1.03B01 devices allow authentication bypass via an AUTHORIZED_GROUP=1 value, as demonstrated by a request for getcfg.php.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| trendnet | tew-752dru_firmware | 1.03b01 |
| trendnet | tew733gr_firmware | 1.03b01 |
| trendnet | tew-751dr_firmware | 1.03b03 |
system.cgi on TRENDnet TV-IP110WN cameras has a buffer overflow caused by an inadequate source-length check before a strcpy operation in the respondAsp function. Attackers can exploit the vulnerability by using the languse parameter with a long string. This affects 1.2.2 build 28, 64, 65, and 68.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-20,CWE-787,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| trendnet | tv-ip110wn_firmware | 1.2.2.65 |
| trendnet | tv-ip110wn_firmware | 1.2.2.28 |
| trendnet | tv-ip110wn_firmware | 1.2.2.68 |
| trendnet | tv-ip110wn_firmware | 1.2.2.64 |
apply.cgi on the TRENDnet TEW-632BRP 1.010B32 router has a buffer overflow via long strings to the SOAPACTION:HNAP1 interface.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| trendnet | tew-632brp_firmware | 1.010b32 |