CVE-2025-25429: XSS
Trendnet TEW-929DRU 1.0.0.10 contains a Stored Cross-site Scripting (XSS) vulnerability via the rname variable inside the havesamename function on the /addschedule.htm page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-25429?
CVE-2025-25429 is classified as a medium severity vulnerability due to the potential for Stored Cross-site Scripting (XSS) attacks.
How do I fix CVE-2025-25429?
To mitigate CVE-2025-25429, users should update the Trendnet TEW-929DRU firmware to the latest version that addresses this security flaw.
What systems are affected by CVE-2025-25429?
CVE-2025-25429 specifically affects the Trendnet TEW-929DRU router running firmware version 1.0.0.10.
What is Stored Cross-site Scripting in the context of CVE-2025-25429?
Stored Cross-site Scripting in CVE-2025-25429 allows attackers to inject malicious scripts that are executed when users access the affected page on the device.
How can I prevent exploitation of CVE-2025-25429?
To prevent exploitation of CVE-2025-25429, it is recommended to implement proper input validation and xss filtering on the affected web functionality.