First published: Fri Jan 26 2024(Updated: )
A vulnerability was found in TRENDnet TEW-800MB 1.0.1.0 and classified as critical. Affected by this issue is some unknown functionality of the component POST Request Handler. The manipulation of the argument DeviceURL leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-252122 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Trendnet Tew-800mb Firmware | =1.0.1.0 | |
TRENDnet TEW-800MB |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-0918 is classified as a critical vulnerability due to its potential for remote code execution via OS command injection.
CVE-2024-0918 affects the POST Request Handler functionality of the Trendnet TEW-800MB firmware.
To mitigate CVE-2024-0918, it is recommended to update the Trendnet TEW-800MB firmware to a patched version if available.
CVE-2024-0918 can lead to OS command injection attacks that may be executed remotely.
CVE-2024-0918 specifically affects Trendnet TEW-800MB firmware version 1.0.1.0.