CVE-2019-11399: Command Injection
Published Dec 18, 2019
·Updated
An issue was discovered on TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices. OS command injection occurs through the getset.ccp lanHostCfgHostName1.1.1.0.0 parameter.
Affected Software
6 affected components
Trendnet Tew-651br Firmware=2.04b1
Trendnet TEW-651BR
Trendnet Tew-652brp Firmware=3.04b01
Trendnet TEW-652BRP
Trendnet Tew-652bru Firmware=1.00b12
Trendnet TEW-652BRU
Event History
Dec 18, 2019
CVE Published
via MITRE·02:52 PM
Data Sourced
via MITRE·02:52 PM
Description
Frequently Asked Questions
1
What is CVE-2019-11399?
CVE-2019-11399 is a vulnerability found on TRENDnet TEW-651BR, TEW-652BRP, and TEW-652BRU devices, allowing OS command injection.
2
How severe is CVE-2019-11399?
CVE-2019-11399 has a severity score of 9.8 (critical).
3
Which devices are affected by CVE-2019-11399?
TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices are affected by CVE-2019-11399.
4
How does OS command injection occur in CVE-2019-11399?
OS command injection occurs through the get_set.ccp lanHostCfg_HostName_1.1.1.0.0 parameter in TRENDnet devices.
5
How can I fix CVE-2019-11399?
It is recommended to update the firmware of the affected devices to mitigate CVE-2019-11399.