Vulnerability Description
An issue was discovered in TRENDnet TEW-824DRU version 1.04b01, allows unauthenticated attackers to execute arbitrary code via the system.ntp.server parameter in the sub_420AE0() function. The attack can be launched remotely.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Trendnet | Tew-824Dru Firmware | 1.04b01 |
| Trendnet | Tew-824Dru | - |
Related Weaknesses (CWE)
References
- https://warp-desk-89d.notion.site/TEW-824DRU-e7228d462ce24fa1a9fecb0bee57caadExploitThird Party Advisory
- https://warp-desk-89d.notion.site/TEW-824DRU-e7228d462ce24fa1a9fecb0bee57caadExploitThird Party Advisory
FAQ
What is CVE-2024-22545?
CVE-2024-22545 is a vulnerability with a CVSS score of 7.8 (HIGH). An issue was discovered in TRENDnet TEW-824DRU version 1.04b01, allows unauthenticated attackers to execute arbitrary code via the system.ntp.server parameter in the sub_420AE0() function. The attack ...
How severe is CVE-2024-22545?
CVE-2024-22545 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-22545?
Check the references section above for vendor advisories and patch information. Affected products include: Trendnet Tew-824Dru Firmware, Trendnet Tew-824Dru.