CVE 5.1 MEDIUM

TRENDnet TEW-831DR formSysCmd command injection_CVE-2025-10107

5.1 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

Description

A vulnerability has been found in TRENDnet TEW-831DR 1.0 (601.130.1.1410). Impacted is an unknown function of the file /boafrm/formSysCmd. The manipulation of the argument sysHost leads to command injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Basic Information

ID CVE-2025-10107
Source VulDB
Published Sep 9, 2025 at 14:32

Affected Product

Vendor TRENDnet
Product TEW-831DR
Version 1.0 (601.130.1.1410)
Affected Versions TRENDnet TEW-831DR 1.0 (601.130.1.1410)

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.