A command injection issue in TRENDnet TEW-411BRPplus v.2.07_eu that allows a local attacker to execute arbitrary code via the data1 parameter in the debug.cgi page.
References
Link | Resource |
---|---|
https://warp-desk-89d.notion.site/TEW-411BRPplus-9bafe26e48964be3be12eab47f77203d | Exploit Third Party Advisory |
https://www.trendnet.com/support/support-detail.asp?prod=160_TEW-411BRPplus | Product |
Configurations
Configuration 1 (hide)
AND |
|
History
No history.
Information
Published : 2024-01-25 22:15
Updated : 2024-01-31 23:32
NVD link : CVE-2023-51833
Mitre link : CVE-2023-51833
CVE.ORG link : CVE-2023-51833
JSON object : View
Products Affected
trendnet
- tew-411brpplus
- tew-411brpplus_firmware
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')