TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS) vulnerability via the ptRule_ApplicationName_1.1.6.0.0 parameter on the /special_ap.htm page.
References
| Link | Resource |
|---|---|
| https://github.com/4hsien/CVE-vulns/blob/main/TRENDnet/TEW-652BRP/XSS_Special_AP/README.md | Exploit Third Party Advisory |
| https://www.trendnet.com/products/product-detail?prod=235_TEW-651BR | Broken Link Product |
| https://www.trendnet.com/products/product-detail?prod=235_TEW-652BRP | Broken Link Product |
| https://www.trendnet.com/products/product-detail?prod=245_TEW-652BRU | Broken Link Product |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
History
No history.
Information
Published : 2024-11-11 20:15
Updated : 2025-04-01 18:21
NVD link : CVE-2024-51190
Mitre link : CVE-2024-51190
CVE.ORG link : CVE-2024-51190
JSON object : View
Products Affected
trendnet
- tew-652bru
- tew-652bru_firmware
- tew-651br
- tew-651br_firmware
- tew-652brp_firmware
- tew-652brp
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
