skip to main content

Annunci

Avvisi sui prodotti, aggiornamenti dei servizi e notifiche del firmware.

TEW-755AP, TEW-821DAP, AND TEW-825DAP HARDWARE VERSION V1.XR WIRELESS ACCESS POINT BUFFER OVERFLOW VULNERABILITIES

TRENDnet has received report of buffer overflow vulnerabilities involving the TEW-755AP, TEW-821DAP, and TEW-825DAP wireless Access Points with hardware version V1.xR that could allow a malicious cyber attacker to take over the device and gain access to its operating system.

TWG-431BR VPN ROUTER AND TEW-740APBO V3.XR WIRELESS ACCESS POINT AUTHENTICATED COMMAND INJECTION VULNERABILITY AND KNOWN VULNERABILITIES IN CLI

TRENDnet is aware of the command injection vulnerability and known vulnerabilities in CLI with TWG-431BR and TEW-740APBO hardware version 3.xR. To exploit these vulnerabilities, the attacker would need to know the device's management interface login user name and password. When exploited successfully, the attacker can compromise the device.

TRENDnet has released firmware updates to address these vulnerabilities

TEW-820AP WIRELESS AC EASY-UPGRADER BUFFER OVERFLOW VULNERABILITIES

TRENDnet is aware of the possible buffer overflow vulnerabilities involving the TEW-820AP Wireless AC Easy-Upgrader that could allow a malicious cyber attacker to take over the device and gain access to its operating system; however, this product has reached its End of Life (EoL) and End of Support, and TRENDnet is unable to provide support to verify or resolve these vulnerabilities.

TRENDnet recommends customers to retire this product to prevent the risk of devices possibly connecting to it.

FRAGMENT and FORGE VULNERABILITIES (FRAGATTACKS) AGAINST SOME WI-FI DEVICES

TRENDnet is aware of a series of published vulnerabilities known as FragAttacks in IEEE 802.11 standard Wi-Fi devices. The affected products are mainly wireless Access Points and Wireless Routers. To exploit these vulnerabilities, the attacker would need to connect to your Wi-Fi network. When exploited successfully, the attacker can extract data from the network, which can lead to additional exploits of your other network devices.

TRENDnet has released firmware updates to address these vulnerabilities for the following products, please click on the link to go to the corresponding product’s download page.

TEW-714TRU TRAVEL ROUTER AUTHENTICATION BYPASS, HARD-CODED CREDENTIALS, AND UNRESTRICTED FILE WRITE VULNERABILITIES

TRENDnet is aware of the vulnerabilities involving the TEW-714TRU Wireless Travel Router that could allow a malicious cyber attacker to take over the router and gain access to its operating system; however, this product has reached its End of Life (EoL) and End of Support, and TRENDnet is unable to provide support to resolve these vulnerabilities.

TRENDnet recommends customers to retire this product to prevent the risk of devices possibly connecting to it.

WEB SERVER DIRECTORY TRAVERSAL ARBITRARY FILE ACCESS VULNERABILITY IN WEB SMART SWITCH TEG-30284 HARDWARE VERSION: 1.0R

TRENDnet recently received a report stating a possible Web Server Directory Traversal Arbitrary File Access vulnerability in the 28-Port Gigabit Web Smart Switch, model TEG-30284, Hardware Version: 1.0R. An attacker may be able to exploit this issue to access sensitive information to aide in subsequent attacks.

CSRF and XSS vulnerabilities in TW100-S4W1CA Hardware V2.0R and V2.1R

TRENDnet was recently made aware of possible CSRF and XSS vulnerabilities in the 4-Port Broadband Router, model TW100-S4W1CA, hardware V2.0R and V2.1R. A Threat Actor can exploit these vulnerabilities and gain control of the router’s management interface.

Buffer overflow vulnerabilities in the Link Layer Discovery Protocol (LLDP) on some of the L2 Managed Industrial Switches

TRENDnet has released firmware patches for buffer overflow vulnerabilities in the Link Layer Discovery Protocol (LLDP) on some of the L2 Managed Industrial Switches. For more information, please visit this page.

TRENDnet CloudView Service End of Life Announcement

September 3, 2020 - TRENDnet CloudView service will be discontinued on December 31, 2020. The cameras running the app and service reached the end of their service life a few years ago, therefore we have decided to discontinue the cloud service for these cameras on December 31, 2020. For more information, please visit www.trendnet.com/camera.

Safari Version 12 Camera Web-View Compatibility

Sept 20, 2018 - Safari version 12 was released Monday for MacOS Sierra and High Sierra users. Version 12 adds new restrictions on browser plugins developers which disables the web-view plugins for the cameras. If users are experiencing problems using Safari with their cameras, we recommend using the Chrome browser for Mac or our free mobile phone app to view the camera.