VYPR

TEW-814DAP

by Trendnet

CVEs (7)

  • CVE-2024-37642CriJun 14, 2024
    risk 0.60cvss 9.1epss 0.11

    TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a command injection vulnerability via the ipv4_ping, ipv6_ping parameter at /formSystemCheck .

  • CVE-2024-0919HigJan 26, 2024
    risk 0.59cvss 8.8epss 0.23

    A vulnerability was found in TRENDnet TEW-815DAP 1.0.2.0. It has been classified as critical. This affects the function do_setNTP of the component POST Request Handler. The manipulation of the argument NtpDstStart/NtpDstEnd leads to command injection. It is possible to initiate…

  • CVE-2024-37645HigJun 14, 2024
    risk 0.57cvss 8.8epss 0.01

    TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a stack overflow vulnerability via the submit-url parameter at /formSysLog .

  • CVE-2024-37643HigJun 14, 2024
    risk 0.57cvss 8.8epss 0.01

    TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a stack overflow vulnerability via the submit-url parameter at /formPasswordAuth .

  • CVE-2024-37641HigJun 14, 2024
    risk 0.57cvss 8.8epss 0.01

    TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a stack overflow via the submit-url parameter at /formNewSchedule

  • CVE-2024-37644HigJun 14, 2024
    risk 0.57cvss 8.8epss 0.00

    TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in as root.

  • CVE-2024-22546MedApr 30, 2024
    risk 0.42cvss 6.4epss 0.01

    TRENDnet TEW-815DAP 1.0.2.0 is vulnerable to Command Injection via the do_setNTP function. An authenticated attacker with administrator privileges can leverage this vulnerability over the network via a malicious POST request.