CVE-2023-51833
Severity CVSS v4.0:
Pending analysis
Type:
CWE-77
Command Injection
Publication date:
25/01/2024
Last modified:
29/05/2025
Description
A command injection issue in TRENDnet TEW-411BRPplus v.2.07_eu that allows a local attacker to execute arbitrary code via the data1 parameter in the debug.cgi page.
Impact
Base Score 3.x
8.10
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:trendnet:tew-411brpplus_firmware:2.07_eu:*:*:*:*:*:*:* | ||
| cpe:2.3:h:trendnet:tew-411brpplus:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://warp-desk-89d.notion.site/TEW-411BRPplus-9bafe26e48964be3be12eab47f77203d
- https://www.trendnet.com/support/support-detail.asp?prod=160_TEW-411BRPplus
- https://warp-desk-89d.notion.site/TEW-411BRPplus-9bafe26e48964be3be12eab47f77203d
- https://www.trendnet.com/support/support-detail.asp?prod=160_TEW-411BRPplus



