OS Command Injection Vulnerability in TRENDnet TEW-713RE Router
CVE-2025-15471
Key Information:
Badges
What is CVE-2025-15471?
A security vulnerability exists in TRENDnet TEW-713RE version 1.02, specifically in the '/goformX/formFSrvX' file. This unknown function allows an attacker to manipulate the 'SZCMD' argument, leading to the possibility of remote OS command injection. The exploit methodology is now publicly available, creating urgent implications for affected users. Despite prompt notification, the vendor has not issued a response, raising concerns about potential exploitation.
Affected Version(s)
TEW-713RE 1.02
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
