TRENDnet TEW-811DRU Web Interface command injection
CVE-2023-0638
9.8CRITICAL
What is CVE-2023-0638?
A command injection vulnerability has been identified in the web interface component of the TRENDnet TEW-811DRU. This issue allows an attacker to execute arbitrary commands on the device from a remote location, posing significant security risks. The affected version is 1.0.10.0, and exploits have been publicly disclosed, emphasizing the urgent need for users to address this vulnerability to protect their networks.
Affected Version(s)
TEW-811DRU 1.0.10.0
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
leetsun (VulDB User)