CVE-2024-37642: Command Injection
Published Jun 14, 2024
·Updated
TRENDnet TEW-814DAP v1(FW1.01B01) was discovered to contain a command injection vulnerability via the ipv4ping, ipv6ping parameter at /formSystemCheck .
Affected Software
3 affected components
Trendnet TEW-814DAP
All of the following
Trendnet Tew-814dap Firmware=1.01b01
Trendnet TEW-814DAP=1.0
Event History
Jun 14, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-37642?
The severity of CVE-2024-37642 is classified as high due to the potential for remote command injection.
2
How do I fix CVE-2024-37642?
To fix CVE-2024-37642, update to the latest firmware version provided by TRENDnet that addresses this vulnerability.
3
What types of attacks can CVE-2024-37642 enable?
CVE-2024-37642 can enable attackers to execute arbitrary commands on the affected device remotely.
4
What devices are affected by CVE-2024-37642?
CVE-2024-37642 specifically affects the TRENDnet TEW-814DAP model with the firmware version 1.01B01.
5
How can I mitigate the risk of CVE-2024-37642?
To mitigate the risk, limit external access to the device and regularly apply firmware updates from TRENDnet.