CVE-2024-51190
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
11/11/2024
Last modified:
01/04/2025
Description
TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS) vulnerability via the ptRule_ApplicationName_1.1.6.0.0 parameter on the /special_ap.htm page.
Impact
Base Score 3.x
4.80
Severity 3.x
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:trendnet:tew-651br_firmware:2.04b1:*:*:*:*:*:*:* | ||
cpe:2.3:h:trendnet:tew-651br:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:trendnet:tew-652brp_firmware:3.04b01:*:*:*:*:*:*:* | ||
cpe:2.3:h:trendnet:tew-652brp:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:trendnet:tew-652bru_firmware:1.00b12:*:*:*:*:*:*:* | ||
cpe:2.3:h:trendnet:tew-652bru:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page