Skip to content

Instantly share code, notes, and snippets.

@powalll
Created August 29, 2025 04:54
Show Gist options
  • Select an option

  • Save powalll/682c1b81696888fd692e595598f2ae3e to your computer and use it in GitHub Desktop.

Select an option

Save powalll/682c1b81696888fd692e595598f2ae3e to your computer and use it in GitHub Desktop.
> [Suggested description]
> TRENDnet TV-IP410 vA1.0R was discovered to contain an OS command
> injection vulnerability via the /server/cgi-bin/testserv.cgi component.
>
> ------------------------------------------
>
> [VulnerabilityType Other]
> CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
>
> ------------------------------------------
>
> [Vendor of Product]
> TRENDnet
>
> ------------------------------------------
>
> [Affected Product Code Base]
> TV-IP410 - Version A1.0R
>
> ------------------------------------------
>
> [Affected Component]
> The webserver used for configuration and testing of camera has vulnerable binary in its firmware: /server/cgi-bin/testserv.cgi
>
> ------------------------------------------
>
> [Attack Type]
> Remote
>
> ------------------------------------------
>
> [Impact Code execution]
> true
>
> ------------------------------------------
>
> [Attack Vectors]
> Insert a command injection payload into a vulnerable testserv.cgi endpoint
>
> ------------------------------------------
>
> [Discoverer]
> Anthony Powall Wang
>
> ------------------------------------------
>
> [Reference]
> http://trendnet.com
> http://tv-ip410.com
Use CVE-2024-46484.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment