CVE-2024-0919 is a critical command injection vulnerability affecting TRENDnet TEW-815DAP firmware version 1.0.2.0. Specifically, the do_setNTP function within the POST Request Handler is susceptible to manipulation of the NtpDstStart/NtpDstEnd arguments. This flaw allows for remote command injection, posing a significant risk to affected devices. The vulnerability carries a CVSS score of 7.2 (HIGH), indicating a high severity due to its network-based attack vector, low attack complexity, and high potential for compromise of confidentiality, integrity, and availability. Despite its criticality, the vendor has not responded to disclosure attempts. While no active exploitation has been confirmed and there are no public exploits in Metasploit, Nuclei, or ExploitDB, the exploit has been publicly disclosed. Community discussion and media coverage for this CVE are currently minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.2.0CPE matchmatch criteria | cpe:2.3:o:trendnet:tew-815dap_firmware:1.0.2.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.