CVE-2024-57590: Command Injection
TRENDnet TEW-632BRP v1.010B31 devices have an OS command injection vulnerability in the CGl interface "ntpsync.cgi",which allows remote attackers to execute arbitrary commands via parameter "ntpserver" passed to the "ntpsync.cgi" binary through a POST request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-57590?
CVE-2024-57590 is rated as a high severity vulnerability due to its OS command injection capabilities.
How do I fix CVE-2024-57590?
To mitigate CVE-2024-57590, update the firmware of the TRENDnet TEW-632BRP device to the latest version provided by the vendor.
What type of vulnerability is CVE-2024-57590?
CVE-2024-57590 is classified as an OS command injection vulnerability.
Which devices are affected by CVE-2024-57590?
CVE-2024-57590 affects TRENDnet TEW-632BRP devices running firmware version v1.010B31.
What can attackers achieve through CVE-2024-57590?
Attackers can execute arbitrary commands on affected devices by exploiting the OS command injection in the ntp_sync.cgi interface.