TRENDnet TEW-800MB
cpe:2.3:h:trendnet:tew-800mb:*:*:*:*:*:*:*, +1 more
- 1.0.1.0
A critical command injection vulnerability has been identified in the TRENDnet TEW-800MB router, specifically in version 1.0.1.0. The issue resides in the NTPSyncWithHost.cgi file, within the sub_F934 function. This vulnerability allows authenticated attackers, or those with a valid CSRF token, to execute arbitrary shell commands with root privileges on the device. The vulnerability can be exploited remotely, and a public proof-of-concept exploit is available.
Exploitation of this vulnerability allows for command injection, with the executed commands running as root on the affected device.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.