CVE-2019-11399
Severity CVSS v4.0:
Pending analysis
Type:
CWE-78
OS Command Injections
Publication date:
18/12/2019
Last modified:
23/12/2019
Description
An issue was discovered on TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices. OS command injection occurs through the get_set.ccp lanHostCfg_HostName_1.1.1.0.0 parameter.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
10.00
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:trendnet:tew-651br_firmware:2.04b1:*:*:*:*:*:*:* | ||
| cpe:2.3:h:trendnet:tew-651br:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:trendnet:tew-652brp_firmware:3.04b01:*:*:*:*:*:*:* | ||
| cpe:2.3:h:trendnet:tew-652brp:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:trendnet:tew-652bru_firmware:1.00b12:*:*:*:*:*:*:* | ||
| cpe:2.3:h:trendnet:tew-652bru:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



