TRENDnet records
190 published records for vendor trendnet.
Researcher profile
- Entered KEV
- 1 · 0.5%
- Weaponized
- 2 · 1.1%
- Pre-auth RCE
- 26
- With a fix record
- 0%
- Median publish → KEV
- 1646 days
Recurring classes
- CWE-787 Out-of-bounds Write37
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')26
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')23
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer17
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')13
- CWE-121 Stack-based Buffer Overflow8
The weakness classes this vendor ships most often: where to look.
CWEAll records
190 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
94Now | CVE-2015-1187Weaponized | The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ctrendnet · tew-731br firmware · CWE-287 | Critical9.8 | KEV | 82.9% | Sep 21, 2017 |
61This week | CVE-2012-4876Weaponized | Stack-based buffer overflow in the UltraMJCam ActiveX Control in TRENDnet SecurView TV-IP121WN Wireless Internet Camera allows remote attacktrendnet · securview wireless internet camera activex control · CWE-119 | Critical10.0 | — | 71.2% | Sep 6, 2012 |
45Plan | CVE-2023-49237No exploit | An issue was discovered on TRENDnet TV-IP1314PI 5.5.3 200714 devices.trendnet · tv-ip1314pi firmware · CWE-77 | Critical9.8 | — | 18.6% | Jan 9, 2024 |
44Plan | CVE-2019-11400No exploit | An issue was discovered on TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices.trendnet · tew-651br firmware · CWE-119 | Critical9.8 | — | 16.6% | Dec 18, 2019 |
43Plan | CVE-2013-4659Proof of concept | Buffer overflow in Broadcom ACSD allows remote attackers to execute arbitrary code via a long string to TCP port 5916.asus · rt-ac66u firmware · CWE-119 | Critical9.8 | — | 13.9% | Mar 14, 2017 |
42Plan | CVE-2021-20158Proof of concept | Trendnet AC2600 TEW-827DRU version 2.08B01 contains an authentication bypass vulnerability.trendnet · tew-827dru firmware · CWE-306 | Critical9.8 | — | 10.9% | Dec 30, 2021 |
42Plan | CVE-2019-13278No exploit | TRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains multiple command injections when processing user input for the setup trendnet · tew-827dru firmware · CWE-78 | Critical9.8 | — | 8.8% | Jul 10, 2019 |
41Plan | CVE-2024-50667No exploit | The boa httpd of Trendnet TEW-820AP 1.01.B01 has a stack overflow vulnerability in /boafrm/formIPv6Addr, /boafrm/formIpv6Setup, /boafrm/formtrendnet · tew-820ap firmware · CWE-120 | Critical9.8 | — | 6.7% | Nov 11, 2024 |
41Plan | CVE-2023-0640No exploit | TRENDnet TEW-652BRP Web Interface ping.ccp command injectiontrendnet · tew-652brp firmware · CWE-77 | Critical9.8 | — | 6.5% | Feb 2, 2023 |
41Plan | CVE-2024-28354No exploit | There is a command injection vulnerability in the TRENDnet TEW-827DRU router with firmware version 2.10B01.trendnet · tew-827dru firmware · CWE-77 | Critical10.0 | — | 2.2% | Mar 15, 2024 |
40Plan | CVE-2018-19240No exploit | Buffer overflow in network.cgi on TRENDnet TV-IP110WN V1.2.2 build 68, V1.2.2.65, and V1.2.2 build 64 and TV-IP121WN V1.2.2 build 28 devicestrendnet · tv-ip110wn firmware · CWE-119 | Critical9.8 | — | 3.7% | Dec 20, 2018 |
40Plan | CVE-2020-12763No exploit | TRENDnet ProView Wireless camera TV-IP512WN 1.0R 1.0.4 is vulnerable to an unauthenticated stack-based buffer overflow in handling RTSP packtrendnet · tv-ip512wn firmware · CWE-787 | Critical9.8 | — | 3.4% | May 13, 2020 |
40Plan | CVE-2019-11399No exploit | An issue was discovered on TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices.trendnet · tew-651br firmware · CWE-78 | Critical9.8 | — | 3.0% | Dec 18, 2019 |
40Plan | CVE-2023-0638No exploit | TRENDnet TEW-811DRU Web Interface command injectiontrendnet · tew-811dru firmware · CWE-77 | Critical9.8 | — | 2.9% | Feb 2, 2023 |
40Plan | CVE-2019-13276No exploit | TRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains a stack-based buffer overflow in the ssi binary.trendnet · tew-827dru firmware · CWE-787 | Critical9.8 | — | 2.8% | Jul 10, 2019 |
40Plan | CVE-2019-13279No exploit | TRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains multiple stack-based buffer overflows when processing user input for trendnet · tew-827dru firmware · CWE-787 | Critical9.8 | — | 2.7% | Jul 10, 2019 |
40Plan | CVE-2013-3367No exploit | Undocumented TELNET service in TRENDnet TEW-691GR and TEW-692GR when a web page named backdoor contains an HTML parameter of password and a trendnet · tew-691gr firmware · CWE-287 | Critical9.8 | — | 2.7% | Nov 13, 2019 |
40Plan | CVE-2020-14080No exploit | TRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary.trendnet · tew-827dru firmware · CWE-787 | Critical9.8 | — | 2.3% | Jun 15, 2020 |
40Plan | CVE-2022-37053No exploit | TRENDnet TEW733GR v1.03B01 is vulnerable to Command injection via /htdocs/upnpinc/gena.php.trendnet · tew733gr firmware · CWE-94 | Critical9.8 | — | 2.3% | Aug 28, 2022 |
40Plan | CVE-2022-46598No exploit | TRENDnet TEW755AP 1.13B01 was discovered to contain a command injection vulnerability via the wps_sta_enrollee_pin parameter in the action strendnet · tew-755ap firmware · CWE-78 | Critical9.8 | — | 2.3% | Dec 30, 2022 |
40Plan | CVE-2022-46597No exploit | TRENDnet TEW755AP 1.13B01 was discovered to contain a command injection vulnerability via the sys_service parameter in the setup_wizard_mydltrendnet · tew-755ap firmware · CWE-78 | Critical9.8 | — | 2.3% | Dec 30, 2022 |
40Plan | CVE-2014-8579No exploit | TRENDnet TEW-823DRU devices with firmware before 1.00b36 have a hardcoded password of kcodeskcodes for the root account, which makes it easitrendnet · tew-823dru firmware · CWE-798 | Critical9.8 | — | 2.0% | Jan 5, 2018 |
40Plan | CVE-2022-30329No exploit | An issue was found on TRENDnet TEW-831DR 1.0 601.130.1.1356 devices.trendnet · tew-831dr firmware · CWE-78 | Critical9.8 | — | 2.0% | Jun 16, 2022 |
40Plan | CVE-2021-20155No exploit | Trendnet AC2600 TEW-827DRU version 2.08B01 makes use of hardcoded credentials.trendnet · tew-827dru firmware · CWE-798 | Critical9.8 | — | 1.9% | Dec 30, 2021 |
40Plan | CVE-2021-20151No exploit | Trendnet AC2600 TEW-827DRU version 2.08B01 contains a flaw in the session management for the device.trendnet · tew-827dru firmware · CWE-384 | Critical10.0 | — | 1.6% | Dec 30, 2021 |
- CVE-2015-118794Now
The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.c
CriticalCVSS 9.8KEVWeaponizedEPSS 83%trendnet · tew-731br firmwareSep 21, 2017
- CVE-2012-487661This week
Stack-based buffer overflow in the UltraMJCam ActiveX Control in TRENDnet SecurView TV-IP121WN Wireless Internet Camera allows remote attack
CriticalCVSS 10.0WeaponizedEPSS 71%trendnet · securview wireless internet camera activex controlSep 6, 2012
- CVE-2023-4923745Plan
An issue was discovered on TRENDnet TV-IP1314PI 5.5.3 200714 devices.
CriticalCVSS 9.8No exploitEPSS 19%trendnet · tv-ip1314pi firmwareJan 9, 2024
- CVE-2019-1140044Plan
An issue was discovered on TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices.
CriticalCVSS 9.8No exploitEPSS 17%trendnet · tew-651br firmwareDec 18, 2019
- CVE-2013-465943Plan
Buffer overflow in Broadcom ACSD allows remote attackers to execute arbitrary code via a long string to TCP port 5916.
CriticalCVSS 9.8Proof of conceptEPSS 14%asus · rt-ac66u firmwareMar 14, 2017
- CVE-2021-2015842Plan
Trendnet AC2600 TEW-827DRU version 2.08B01 contains an authentication bypass vulnerability.
CriticalCVSS 9.8Proof of conceptEPSS 11%trendnet · tew-827dru firmwareDec 30, 2021
- CVE-2019-1327842Plan
TRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains multiple command injections when processing user input for the setup
CriticalCVSS 9.8No exploitEPSS 9%trendnet · tew-827dru firmwareJul 10, 2019
- CVE-2024-5066741Plan
The boa httpd of Trendnet TEW-820AP 1.01.B01 has a stack overflow vulnerability in /boafrm/formIPv6Addr, /boafrm/formIpv6Setup, /boafrm/form
CriticalCVSS 9.8No exploitEPSS 7%trendnet · tew-820ap firmwareNov 11, 2024
- CVE-2023-064041Plan
TRENDnet TEW-652BRP Web Interface ping.ccp command injection
CriticalCVSS 9.8No exploitEPSS 7%trendnet · tew-652brp firmwareFeb 2, 2023
- CVE-2024-2835441Plan
There is a command injection vulnerability in the TRENDnet TEW-827DRU router with firmware version 2.10B01.
CriticalCVSS 10.0No exploitEPSS 2%trendnet · tew-827dru firmwareMar 15, 2024
- CVE-2018-1924040Plan
Buffer overflow in network.cgi on TRENDnet TV-IP110WN V1.2.2 build 68, V1.2.2.65, and V1.2.2 build 64 and TV-IP121WN V1.2.2 build 28 devices
CriticalCVSS 9.8No exploitEPSS 4%trendnet · tv-ip110wn firmwareDec 20, 2018
- CVE-2020-1276340Plan
TRENDnet ProView Wireless camera TV-IP512WN 1.0R 1.0.4 is vulnerable to an unauthenticated stack-based buffer overflow in handling RTSP pack
CriticalCVSS 9.8No exploitEPSS 3%trendnet · tv-ip512wn firmwareMay 13, 2020
- CVE-2019-1139940Plan
An issue was discovered on TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices.
CriticalCVSS 9.8No exploitEPSS 3%trendnet · tew-651br firmwareDec 18, 2019
- CVE-2023-063840Plan
TRENDnet TEW-811DRU Web Interface command injection
CriticalCVSS 9.8No exploitEPSS 3%trendnet · tew-811dru firmwareFeb 2, 2023
- CVE-2019-1327640Plan
TRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains a stack-based buffer overflow in the ssi binary.
CriticalCVSS 9.8No exploitEPSS 3%trendnet · tew-827dru firmwareJul 10, 2019
- CVE-2019-1327940Plan
TRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains multiple stack-based buffer overflows when processing user input for
CriticalCVSS 9.8No exploitEPSS 3%trendnet · tew-827dru firmwareJul 10, 2019
- CVE-2013-336740Plan
Undocumented TELNET service in TRENDnet TEW-691GR and TEW-692GR when a web page named backdoor contains an HTML parameter of password and a
CriticalCVSS 9.8No exploitEPSS 3%trendnet · tew-691gr firmwareNov 13, 2019
- CVE-2020-1408040Plan
TRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary.
CriticalCVSS 9.8No exploitEPSS 2%trendnet · tew-827dru firmwareJun 15, 2020
- CVE-2022-3705340Plan
TRENDnet TEW733GR v1.03B01 is vulnerable to Command injection via /htdocs/upnpinc/gena.php.
CriticalCVSS 9.8No exploitEPSS 2%trendnet · tew733gr firmwareAug 28, 2022
- CVE-2022-4659840Plan
TRENDnet TEW755AP 1.13B01 was discovered to contain a command injection vulnerability via the wps_sta_enrollee_pin parameter in the action s
CriticalCVSS 9.8No exploitEPSS 2%trendnet · tew-755ap firmwareDec 30, 2022
- CVE-2022-4659740Plan
TRENDnet TEW755AP 1.13B01 was discovered to contain a command injection vulnerability via the sys_service parameter in the setup_wizard_mydl
CriticalCVSS 9.8No exploitEPSS 2%trendnet · tew-755ap firmwareDec 30, 2022
- CVE-2014-857940Plan
TRENDnet TEW-823DRU devices with firmware before 1.00b36 have a hardcoded password of kcodeskcodes for the root account, which makes it easi
CriticalCVSS 9.8No exploitEPSS 2%trendnet · tew-823dru firmwareJan 5, 2018
- CVE-2022-3032940Plan
An issue was found on TRENDnet TEW-831DR 1.0 601.130.1.1356 devices.
CriticalCVSS 9.8No exploitEPSS 2%trendnet · tew-831dr firmwareJun 16, 2022
- CVE-2021-2015540Plan
Trendnet AC2600 TEW-827DRU version 2.08B01 makes use of hardcoded credentials.
CriticalCVSS 9.8No exploitEPSS 2%trendnet · tew-827dru firmwareDec 30, 2021
- CVE-2021-2015140Plan
Trendnet AC2600 TEW-827DRU version 2.08B01 contains a flaw in the session management for the device.
CriticalCVSS 10.0No exploitEPSS 2%trendnet · tew-827dru firmwareDec 30, 2021