MEDIUM
TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS) vulnerability via the vsRule_VirtualServerName_1.1.10.0.0 parameter on the /virtual_server.htm page
Published Nov 11, 2024
4.8
MEDIUMCVSS 3.1
EPSS 0.39%
Description
TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS) vulnerability via the vsRule_VirtualServerName_1.1.10.0.0 parameter on the /virtual_server.htm page.
Affected products
No data.
Configuration 1
AND
- 2.04b1
Configuration 2
AND
- 3.04b01
Running on/with
- n/a
Configuration 3
AND
- 1.00b12
Running on/with
- n/a
-
- Version 2.04b1StatusaffectedConstraints-
- Version
-
- Version 3.04b01StatusaffectedConstraints-
- Version
-
- Version 1.00b12StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Trendnet | Tew-651br Firmware | n/a |
| ||||||
| Trendnet | Tew-652brp Firmware | n/a |
| ||||||
| Trendnet | Tew-652bru Firmware | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-45299 Advisory
- https://github.com/4hsien/CVE-vulns/blob/main/TRENDnet/TEW-652BRP/XSS_Virtual_Server/README.md ExploitThird Party Advisory
- https://www.trendnet.com/products/product-detail?prod=235_TEW-651BR Broken LinkProduct
- https://www.trendnet.com/products/product-detail?prod=235_TEW-652BRP Broken LinkProduct
- https://www.trendnet.com/products/product-detail?prod=245_TEW-652BRU Broken LinkProduct
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-45299 | Advisory | |
| https://github.com/4hsien/CVE-vulns/blob/main/TRENDnet/TEW-652BRP/XSS_Virtual_Server/README.md | ExploitThird Party Advisory | |
| https://www.trendnet.com/products/product-detail?prod=235_TEW-651BR | Broken LinkProduct | |
| https://www.trendnet.com/products/product-detail?prod=235_TEW-652BRP | Broken LinkProduct | |
| https://www.trendnet.com/products/product-detail?prod=245_TEW-652BRU | Broken LinkProduct |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 11, 2024
Updated Nov 12, 2024
Reserved Oct 28, 2024
Link CVE-2024-51188
CISA Vulnrichment
Updated Nov 12, 2024
ENISA EUVD
EUVD-2024-45299 Assigner mitre
Published Nov 11, 2024
Updated Nov 12, 2024
Exploited since n/a
Link EUVD-2024-45299