Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
TRENDnet TEW-821DAP Firmware Update system_ntp sub_41FBD0 os command injection
Vulnerability Description
A vulnerability was found in TRENDnet TEW-821DAP 1.11B03. This impacts the function sub_41FBD0 of the file /goform/system_ntp of the component Firmware Update Handler. Performing a manipulation of the argument Hostname results in os command injection. The attack may be initiated remotely. The vendor explains: "We are unable to confirm the existence of the vulnerabilities for (...) TEW-821DAP (v1.0R) as these items have been EOL. " This vulnerability only affects products that are no longer supported by the maintainer.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
TRENDnet TEW-821DAP 命令注入漏洞
Vulnerability Description
TRENDnet tew-821dap是美国TRENDnet公司的一款无线接入点。 TRENDnet TEW-821DAP 1.11B03版本存在命令注入漏洞,该漏洞源于文件/goform/system_ntp中参数Hostname的错误操作,可能导致操作系统命令注入。
CVSS Information
N/A
Vulnerability Type
N/A