First published: Fri Feb 28 2025(Updated: )
Trendnet TEW-929DRU 1.0.0.10 contains a Stored Cross-site Scripting (XSS) vulnerability via the The ssid key of wifi_data parameter on the /captive_portal.htm page.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Trendnet TEW-929DRU |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-25431 is classified as a Stored Cross-site Scripting (XSS) vulnerability.
To fix CVE-2025-25431, update your Trendnet TEW-929DRU router to the latest firmware version provided by Trendnet.
CVE-2025-25431 affects Trendnet TEW-929DRU version 1.0.0.10.
The attack vector for CVE-2025-25431 involves the ssid key of the wifi_data parameter on the /captive_portal.htm page.
CVE-2025-25431 is a Stored Cross-site Scripting (XSS) vulnerability that allows attackers to execute scripts in a victim's browser.