Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

TRENDnet — Vulnerabilities & Security Advisories 90

Browse all 90 CVE security advisories affecting TRENDnet. AI-powered Chinese analysis, POCs, and references for each vulnerability.

TRENDnet operates primarily as a manufacturer of consumer and small business networking hardware, including routers, switches, and IP cameras. Security audits have identified forty-five Common Vulnerabilities and Exposures (CVEs) associated with its product lines, highlighting systemic weaknesses in embedded software development. Historically, these vulnerabilities frequently manifest as remote code execution (RCE) and cross-site scripting (XSS), often stemming from inadequate input validation in web management interfaces. Privilege escalation flaws are also prevalent, allowing unauthenticated attackers to gain administrative control over devices. Notable incidents include the exploitation of default credentials and hardcoded secrets in older camera models, which facilitated large-scale botnet recruitment. The company’s security posture has faced criticism for delayed firmware updates and limited transparency regarding patch cycles. These recurring issues underscore significant challenges in securing IoT infrastructure, where resource constraints often compromise robust authentication and encryption mechanisms.

CVE ID Title CVSS Severity Published
CVE-2026-4354 TRENDnet TEW-824DRU Web apply_sec.cgi sub_420A78 cross site scripting — TEW-824DRU CWE-79 3.5 Low 2026-03-17
CVE-2026-4172 TRENDnet TEW-632BRP HTTP POST Request ping_response.cgi stack-based overflow — TEW-632BRP CWE-121 7.2 High 2026-03-15
CVE-2025-15472 TRENDnet TEW-811DRU httpd  uapply.cgi setDeviceURL  os command injection — TEW-811DRU CWE-78 7.2 High 2026-01-06
CVE-2025-15471 TRENDnet TEW-713RE formFSrvX os command injection — TEW-713RE CWE-78 9.8 Critical 2026-01-06
CVE-2025-15139 TRENDnet TEW-822DRE formWsc sub_43ACF4  command injection — TEW-822DRE CWE-77 6.3 Medium 2025-12-28
CVE-2025-15137 TRENDnet TEW-800MB NTPSyncWithHost.cgi sub_F934  command injection — TEW-800MB CWE-77 8.8 High 2025-12-28
CVE-2025-15136 TRENDnet TEW-800MB Management wizardset do_setWizard_asp command injection — TEW-800MB CWE-77 8.8 High 2025-12-28
CVE-2025-10107 TRENDnet TEW-831DR formSysCmd command injection — TEW-831DR CWE-77 4.7 Medium 2025-09-09
CVE-2025-8759 TRENDnet TN-200 Lighttpd hard-coded key — TN-200 CWE-321 3.7 Low 2025-08-09
CVE-2025-8758 TRENDnet TEW-822DRE vsftpd least privilege violation — TEW-822DRE CWE-272 7.0 High 2025-08-09
CVE-2025-8757 TRENDnet TV-IP110WN Embedded Boa Web Server boa.conf least privilege violation — TV-IP110WN CWE-272 7.0 High 2025-08-09
CVE-2025-8731 TRENDnet TI-G160i/TI-PG102i/TPL-430AP SSH Service default credentials — TI-G160i CWE-1392 9.8 Critical 2025-08-08
CVE-2025-5870 TRENDnet TV-IP121W Web Interface setup.cgi improper authentication — TV-IP121W CWE-287 7.3 High 2025-06-09
CVE-2025-2960 TRENDnet TEW-637AP/TEW-638APB HTTP Request goahead sub_41DED0 null pointer dereference — TEW-637AP CWE-476 6.5 Medium 2025-03-30
CVE-2025-2959 TRENDnet TEW-410APB HTTP Request httpd sub_4019A0 null pointer dereference — TEW-410APB CWE-476 6.5 Medium 2025-03-30
CVE-2025-2958 TRENDnet TEW-818DRU HTTP Request httpd denial of service — TEW-818DRU CWE-404 6.5 Medium 2025-03-30
CVE-2025-2957 TRENDnet TEW-411BRP+ HTTP Request httpd sub_401DB0 null pointer dereference — TEW-411BRP+ CWE-476 6.5 Medium 2025-03-30
CVE-2025-2956 TRENDnet TI-G102i HTTP Request lighttpd plugins_call_handle_uri_raw null pointer dereference — TI-G102i CWE-476 6.5 Medium 2025-03-30
CVE-2024-0920 TRENDnet TEW-822DRE POST Request admin_ping.htm command injection — TEW-822DRE CWE-77 7.2 High 2024-01-26
CVE-2024-0919 TRENDnet TEW-815DAP POST Request do_setNTP command injection — TEW-815DAP CWE-77 8.8 High 2024-01-26
CVE-2024-0918 TRENDnet TEW-800MB POST Request os command injection — TEW-800MB CWE-78 7.2 High 2024-01-26
CVE-2023-0640 TRENDnet TEW-652BRP Web Interface ping.ccp command injection — TEW-652BRP CWE-77 7.2 High 2023-02-02
CVE-2023-0639 TRENDnet TEW-652BRP Web Management Interface get_set.ccp cross site scripting — TEW-652BRP CWE-79 2.4 Low 2023-02-02
CVE-2023-0638 TRENDnet TEW-811DRU Web Interface command injection — TEW-811DRU CWE-77 7.2 High 2023-02-02
CVE-2023-0637 TRENDnet TEW-811DRU Web Management Interface wan.asp memory corruption — TEW-811DRU CWE-119 6.5 Medium 2023-02-02
CVE-2023-0618 TRENDnet TEW-652BRP Web Service cfg_op.ccp memory corruption — TEW-652BRP CWE-119 7.5 High 2023-02-01
CVE-2023-0617 TRENDNet TEW-811DRU httpd guestnetwork.asp buffer overflow — TEW-811DRU CWE-120 7.5 High 2023-02-01
CVE-2023-0613 TRENDnet TEW-811DRU httpd security.asp memory corruption — TEW-811DRU CWE-119 7.5 High 2023-02-01
CVE-2023-0612 TRENDnet TEW-811DRU httpd basic.asp buffer overflow — TEW-811DRU CWE-120 7.5 High 2023-02-01
CVE-2023-0611 TRENDnet TEW-652BRP Web Management Interface get_set.ccp command injection — TEW-652BRP CWE-77 8.8 High 2023-02-01

This page lists every published CVE security advisory associated with TRENDnet. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.