← Back to browse · API

CVE-2025-15472

Severity
HIGH
CVSS
8.6
EPSS
0.20427
Risk score
41.55
CISA KEV
No
PoC
No
Published
2026-01-06
Modified
2026-02-23
First seen
2026-08-06
Aliases
CNVD-2026-17705, EUVD-2025-206249, GHSA-G6RC-W49H-G45H
Products
TRENDnet TEW-811DRU 1.0.2.0, TRENDnet:TEW-811DRU 1.0.2.0
Sources
cnvd CNVD-2026-17705
euvd EUVD-2025-206249

Description

A flaw has been found in TRENDnet TEW-811DRU 1.0.2.0. This affects the function setDeviceURL  of the file uapply.cgi of the component httpd . This manipulation of the argument DeviceURL causes os command injection. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

References