VYPR
Vendor

Trendnet

Products
123
CVEs
223
Across products
330
Status
Private

Products

123
View all 123 products →

Recent CVEs

223
View all 223 CVEs →
  • CVE-2015-1187CriKEVSep 21, 2017
    risk 0.85cvss 9.8epss 0.83

    The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ccp.

  • CVE-2013-4659CriMar 14, 2017
    risk 0.68cvss 9.8epss 0.14

    Buffer overflow in Broadcom ACSD allows remote attackers to execute arbitrary code via a long string to TCP port 5916. This component is used on routers of multiple vendors including ASUS RT-AC66U and TRENDnet TEW-812DRU.

  • CVE-2025-15471CriJan 7, 2026
    risk 0.65cvss 9.8epss 0.12

    A vulnerability was detected in TRENDnet TEW-713RE 1.02. The impacted element is an unknown function of the file /goformX/formFSrvX. The manipulation of the argument SZCMD results in os command injection. It is possible to launch the attack remotely. The exploit is now public…

  • CVE-2024-28354CriMar 15, 2024
    risk 0.65cvss 10.0epss 0.02

    There is a command injection vulnerability in the TRENDnet TEW-827DRU router with firmware version 2.10B01. An attacker can inject commands into the post request parameters usapps.@smb[%d].username in the apply.cgi interface, thereby gaining root shell privileges.

  • CVE-2023-49237CriJan 9, 2024
    risk 0.65cvss 9.8epss 0.19

    An issue was discovered on TRENDnet TV-IP1314PI 5.5.3 200714 devices. Command injection can occur because the system function is used by davinci to unpack language packs without strict filtering of URL strings.

  • CVE-2021-20158CriDec 30, 2021
    risk 0.65cvss 9.8epss 0.11

    Trendnet AC2600 TEW-827DRU version 2.08B01 contains an authentication bypass vulnerability. It is possible for an unauthenticated, malicous actor to force the change of the admin password due to a hidden administrative command.

  • CVE-2021-20151CriDec 30, 2021
    risk 0.65cvss 10.0epss 0.02

    Trendnet AC2600 TEW-827DRU version 2.08B01 contains a flaw in the session management for the device. The router's management software manages web sessions based on IP address rather than verifying client cookies/session tokens/etc. This allows an attacker (whether from a…

  • CVE-2019-11400CriDec 18, 2019
    risk 0.65cvss 9.8epss 0.17

    An issue was discovered on TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices. A buffer overflow occurs through the get_set.ccp ccp_act parameter.

  • CVE-2024-46484CriAug 29, 2025
    risk 0.64cvss 9.8epss 0.01

    TRENDnet TV-IP410 vA1.0R was discovered to contain an OS command injection vulnerability via the /server/cgi-bin/testserv.cgi component.

  • CVE-2025-8731CriAug 8, 2025
    risk 0.64cvss 9.8epss 0.01

    A vulnerability was identified in TRENDnet TI-G160i, TI-PG102i and TPL-430AP up to 20250724. This affects an unknown part of the component SSH Service. The manipulation leads to use of default credentials. It is possible to initiate the attack remotely. The exploit has been…

  • CVE-2024-57590CriJan 27, 2025
    risk 0.64cvss 9.8epss 0.01

    TRENDnet TEW-632BRP v1.010B31 devices have an OS command injection vulnerability in the CGl interface "ntp_sync.cgi",which allows remote attackers to execute arbitrary commands via parameter "ntp_server" passed to the "ntp_sync.cgi" binary through a POST request.

  • CVE-2024-50667CriNov 11, 2024
    risk 0.64cvss 9.8epss 0.06

    The boa httpd of Trendnet TEW-820AP 1.01.B01 has a stack overflow vulnerability in /boafrm/formIPv6Addr, /boafrm/formIpv6Setup, /boafrm/formDnsv6. The reason is that the check of ipv6 address is not sufficient, which allows attackers to construct payloads for attacks.

  • CVE-2024-42813CriAug 19, 2024
    risk 0.64cvss 9.8epss 0.01

    In TRENDnet TEW-752DRU FW1.03B01, there is a buffer overflow vulnerability due to the lack of length verification for the service field in gena.cgi. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands.

  • CVE-2023-49236CriJan 9, 2024
    risk 0.64cvss 9.8epss 0.01

    A stack-based buffer overflow was discovered on TRENDnet TV-IP1314PI 5.5.3 200714 devices, leading to arbitrary command execution. This occurs because of lack of length validation during an sscanf of a user-entered scale field in the RTSP playback function of davinci.

  • CVE-2023-49235CriJan 9, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in libremote_dbg.so on TRENDnet TV-IP1314PI 5.5.3 200714 devices. Filtering of debug information is mishandled during use of popen. Consequently, an attacker can bypass validation and execute a shell command.

  • CVE-2022-46601CriDec 30, 2022
    risk 0.64cvss 9.8epss 0.01

    TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the setbg_num parameter in the icp_setbg_img (sub_41DD68) function.

  • CVE-2022-46600CriDec 30, 2022
    risk 0.64cvss 9.8epss 0.01

    TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the wps_sta_enrollee_pin parameter in the action set_sta_enrollee_pin_24g function.

  • CVE-2022-46599CriDec 30, 2022
    risk 0.64cvss 9.8epss 0.01

    TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the setlogo_num parameter in the icp_setlogo_img (sub_41DBF4) function.

  • CVE-2022-46598CriDec 30, 2022
    risk 0.64cvss 9.8epss 0.02

    TRENDnet TEW755AP 1.13B01 was discovered to contain a command injection vulnerability via the wps_sta_enrollee_pin parameter in the action set_sta_enrollee_pin_5g function.

  • CVE-2022-46597CriDec 30, 2022
    risk 0.64cvss 9.8epss 0.02

    TRENDnet TEW755AP 1.13B01 was discovered to contain a command injection vulnerability via the sys_service parameter in the setup_wizard_mydlink (sub_4104B8) function.