Created
August 29, 2025 04:54
-
-
Save powalll/682c1b81696888fd692e595598f2ae3e to your computer and use it in GitHub Desktop.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| > [Suggested description] | |
| > TRENDnet TV-IP410 vA1.0R was discovered to contain an OS command | |
| > injection vulnerability via the /server/cgi-bin/testserv.cgi component. | |
| > | |
| > ------------------------------------------ | |
| > | |
| > [VulnerabilityType Other] | |
| > CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | |
| > | |
| > ------------------------------------------ | |
| > | |
| > [Vendor of Product] | |
| > TRENDnet | |
| > | |
| > ------------------------------------------ | |
| > | |
| > [Affected Product Code Base] | |
| > TV-IP410 - Version A1.0R | |
| > | |
| > ------------------------------------------ | |
| > | |
| > [Affected Component] | |
| > The webserver used for configuration and testing of camera has vulnerable binary in its firmware: /server/cgi-bin/testserv.cgi | |
| > | |
| > ------------------------------------------ | |
| > | |
| > [Attack Type] | |
| > Remote | |
| > | |
| > ------------------------------------------ | |
| > | |
| > [Impact Code execution] | |
| > true | |
| > | |
| > ------------------------------------------ | |
| > | |
| > [Attack Vectors] | |
| > Insert a command injection payload into a vulnerable testserv.cgi endpoint | |
| > | |
| > ------------------------------------------ | |
| > | |
| > [Discoverer] | |
| > Anthony Powall Wang | |
| > | |
| > ------------------------------------------ | |
| > | |
| > [Reference] | |
| > http://trendnet.com | |
| > http://tv-ip410.com | |
| Use CVE-2024-46484. |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment