Vulnerability Description
TRENDnet TEW-815DAP 1.0.2.0 is vulnerable to Command Injection via the do_setNTP function. An authenticated attacker with administrator privileges can leverage this vulnerability over the network via a malicious POST request.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Trendnet | Tew-815Dap Firmware | 1.0.2.0 |
| Trendnet | Tew-815Dap | - |
Related Weaknesses (CWE)
References
- https://warp-desk-89d.notion.site/TEW-815DAP-94a631c20dee4f399268dbcc880f1f4cExploitThird Party Advisory
- https://www.trendnet.com/support/support-detail.asp?prod=105_TEW-815DAPBroken LinkVendor Advisory
- https://warp-desk-89d.notion.site/TEW-815DAP-94a631c20dee4f399268dbcc880f1f4cExploitThird Party Advisory
- https://www.trendnet.com/support/support-detail.asp?prod=105_TEW-815DAPBroken LinkVendor Advisory
FAQ
What is CVE-2024-22546?
CVE-2024-22546 is a vulnerability with a CVSS score of 6.4 (MEDIUM). TRENDnet TEW-815DAP 1.0.2.0 is vulnerable to Command Injection via the do_setNTP function. An authenticated attacker with administrator privileges can leverage this vulnerability over the network via ...
How severe is CVE-2024-22546?
CVE-2024-22546 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-22546?
Check the references section above for vendor advisories and patch information. Affected products include: Trendnet Tew-815Dap Firmware, Trendnet Tew-815Dap.