漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
TRENDnet TEW-432BRP formSetRoute command injection
Vulnerability Description
A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. This impacts the function formSetRoute of the file /goform/formSetRoute. The manipulation of the argument ip/mask/gateway leads to command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities." This vulnerability only affects products that are no longer supported by the maintainer.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
在命令中使用的特殊元素转义处理不恰当(命令注入)
Vulnerability Title
TRENDnet TEW-432BRP 安全漏洞
Vulnerability Description
TRENDnet TEW-432BRP是美国趋势网络(TRENDnet)公司的一款双频无线路由器。 TRENDnet TEW-432BRP 3.10B20版本存在安全漏洞,该漏洞源于文件/goform/formSetRoute中参数ip/mask/gateway命令注入,可能导致远程攻击者执行命令。
CVSS Information
N/A
Vulnerability Type
N/A