CVE-2025-15472: TRENDnet TEW-811DRU httpd uapply.cgi setDeviceURL os command injection
A flaw has been found in TRENDnet TEW-811DRU 1.0.2.0. This affects the function setDeviceURL of the file uapply.cgi of the component httpd . This manipulation of the argument DeviceURL causes os command injection. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15472?
The severity of CVE-2025-15472 is considered high due to its potential for remote command execution.
How do I fix CVE-2025-15472?
To fix CVE-2025-15472, update the TRENDnet TEW-811DRU firmware to the latest version that addresses this vulnerability.
What component is affected by CVE-2025-15472?
CVE-2025-15472 affects the httpd component, specifically the setDeviceURL function in the uapply.cgi file.
Can CVE-2025-15472 be exploited remotely?
Yes, CVE-2025-15472 can be exploited remotely, allowing attackers to execute OS commands.
What devices are impacted by CVE-2025-15472?
The TRENDnet TEW-811DRU version 1.0.2.0 is impacted by CVE-2025-15472.