TRENDnet TEW-652BRP Web Management Interface get_set.ccp command injection
CVE-2023-0611
8.8HIGH
What is CVE-2023-0611?
A command injection vulnerability has been identified in the web management interface of TRENDnet's TEW-652BRP router. This issue arises from the improper handling of the get_set.ccp file, enabling attackers to execute arbitrary commands remotely. Public disclosure of the exploit raises concerns regarding potential unauthorized access and system compromise. It is crucial for users to apply available patches and monitor for suspicious activity to mitigate risks associated with this vulnerability.
Affected Version(s)
TEW-652BRP 3.04B01
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
leetsun (VulDB User)