TEW-831DR AC1200 dual-band Wi-Fi router authenticated command line injection/remote code execution vulnerability
TRENDnet is aware of an authenticated command line injection/remote code execution vulnerability in a configuration setup page involving Wi-Fi router TEW-831DR (firmware version V1.0). When exploited successfully, the intruder can make the router unusable or gain access to its operating system.
Please note that this router has reached its End of Life (EOL) and End of Support, and TRENDnet is unable to provide a solution to address this vulnerability or provide additional support. Although exploring this vulnerability requires the router’s management login user name and password, TRENDnet recommends customer to retire these products to prevent risk of devices possibly connected to it.
TEW-929DRU DUAL-BAND WIFI ROUTER CROSS-SITE SCRIPTING VULNERABILITY
TRENDnet is aware of the CVE-2025-25428
We believe CVE-2025-25428 does not affect the product, because it requires the intruders to first login to the device, but each device has aunique password.
For the cross-site script vulnerability, when exploited successfully, the intruder can redirect user’s web browser to malicious website. TRENDnet has released firmware update to address the vulnerability, please click on the link below to go to the product's firmware download page. Or, you can login to the router's management page using web browser (http://tew-929dru ), click on “Management” on the left, click on “Firmware/Configuration”, click on “CHECK” under “Online Firmware Upgrade”, and then follow the on-screen instruction to upgrade the firmware.
https://www.trendnet.com/support/support-detail.asp?prod=135_TEW-929DRU
LEGACY PRODUCTS: TEW-410APBP+, TEW-411APBP+, TEW-637AP HARDWARE VERSION V2.0R, TEW-638AP HARDWARE VERSION V2.0R, AND TEW-818DRU HARDWARE VERSION V1.XR POSSIBLE LOCAL AREA NETWORK (LAN) DENIAL OF SERVICE (DOS) VULNERABILITY
TRENDnet has received reports of Local Area Network (LAN) Denial of Service (DoS) vulnerability involving legacy Wi-Fi routers: TEW-411BRP+ firmware 2.07 and TEW-818DRU hardware version V1.xR (firmware 1.0.14.6), and legacy Wi-Fi Access Points: TEW-410APB+ (firmware 1.3.06b), TEW-637AP hardware version V2.0R (firmware 1.3.0.106), and TEW-638AP hardware version V2.0R (firmware 1.2.7). These products have reached their End of Life (EOL) and End of Support, and TRENDnet is unable to provide additional support. TRENDnet recommends customers to retire these products to prevent risk of devices possibly connected to it.
TEW-820AP Wireless AC Upgrader Possible stack overflow vulnerability
TRENDnet has received report of a possible stack overflow vulnerability involving TEW-820AP Wireless AC Upgrader that could allow a malicious cyber attacker to make the product unusable or gain access to its operating system; however, this product has reached its End of Life (EOL) and End of Support, and TRENDnet is unable to verify the vulnerability or provide additional support. TRENDnet recommends customer to retire the product to prevent risk of devices possibly connected to it.
TEW-651BR hardware version V2.3R, TEW-652BRP hardware version V3.0R, and TEW-652BRU hardware version V1.0R Wi-Fi Routers possible cross-site scripting (XSS) vulnerability
TRENDnet is aware of a possible cross-site scripting (XSS) vulnerability in a few of the configuration setup pages involving wi-fi router TEW-651BR hardware version V2.3R (firmware 2.04B1), TEW-652BRP hardware version V3.0R (firmware 3.04B01), and TEW-652BRU hardware version V1.0R (firmware 1.00b12); however, these products have reached their End of Life (EOL) and End of Support, and TRENDnet is unable to verify the vulnerability or provide additional support. TRENDnet recommends customer to retire these products to prevent risk of devices possibly connected to it.
TEW-752DRU WIRELESS ROUTER POSSIBLE BUFFER OVERFLOW VULNERABILITY
TRENDnet is aware of a possible buffer overflow vulnerability involving TEW-752DRU Wireless router that could allow a malicious cyber attacker to make the router unusable or gain access to its operating system; however, this product has reached its End of Life (EOL) and End of Support, and TRENDnet is unable to verify the vulnerability or provide additional support. TRENDnet recommends customer to retire the product to prevent risk of devices possibly connected to it.
TEW-829DRU WIRELESS ROUTER COMMAND INJECTION VULNERABILITY
TRENDnet has received report of a command injection vulnerability when the RADIUS authentication is enabled with TEW-829DRU hardware version v1.xR, firmware 1.0.3.9 and earlier. When exploited successfully, the attacker can have root access to the device. TRENDnet has released firmware update to address the vulnerability.
TV-IP422W WIRELESS NETWORK CAMERA REMOTE CODE EXECUTION VULNERABILITY
TRENDnet is aware of a possible Remote Code Execution (RCE) vulnerability involving TV-IP422W Wireless Network Camera that could allow a malicious cyber attacker to take over the camera and gain access to its operating system; however, this product has reached its End of Life (EOL) and End of Support, and TRENDnet is unable to verify the vulnerability or provide additional support. TRENDnet recommends customer to retire the product to prevent risk of devices possibly connected to it.
TEW-841APO and TEW-840APBO WIRELESS ACCESS POINT lighttpd WEB SERVER VULNERABILITY PATCH
TRENDnet has posted new firmware for TEW-840APBO and TEW-841APBO wireless Access Points. The firmware updates the Access Point's lighttpd web server to version 1.4.54, which addresses vulnerabilities.
TEW-827DRU WIRELESS ROUTER COMMAND INJECTION VULNERABILITIES
TRENDnet has received report of the command injection vulnerability and known vulnerabilities in the cgi interface with TEW-827DRU hardware version 2.xR Firmware 2.10.B01 and earlier. When exploited successfully, the attacker can have root access to the device. TRENDnet has released firmware update to address these vulnerabilities, please click on the link below to go to the product's download page. Or, you can login to the device's management (http://TEW-827DRU) and click on the new firmware available notification on the upper right hand side to perform the firmware upgrade.
