VulnerabilityAnalyzed
CVE-2023-51835
An issue in TRENDnet TEW-822DRE v.1.03B02 allows a local attacker to execute arbitrary code via the parameters ipv4_ping in the /boafrm/formSystemCheck.
MEDIUM 6.8EPSS 7.32%
Does this matter?
Lower severity and a low EPSS score (7.32%). Track it; it rarely justifies an emergency change on its own.
Description
An issue in TRENDnet TEW-822DRE v.1.03B02 allows a local attacker to execute arbitrary code via the parameters ipv4_ping in the /boafrm/formSystemCheck.
- CVSS 3.1
- 6.8 MEDIUMCVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 7.32% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-77
- Affected
- trendnet/tew-822dre firmware
- Source
- cve@mitre.org
References
- https://warp-desk-89d.notion.site/TEW-822DRE-5289eb95796749c2878843519ab451d8Exploit, Third Party Advisory
- https://www.trendnet.com/support/support-detail.asp?prod=105_TEW-822DREProduct
- https://warp-desk-89d.notion.site/TEW-822DRE-5289eb95796749c2878843519ab451d8Exploit, Third Party Advisory
- https://www.trendnet.com/support/support-detail.asp?prod=105_TEW-822DREProduct
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.