Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Trendnet

First CVE: Sep 6, 2012Active for: 14 yearsTotal CVEs: 190
66.3
VTI Score
TOP TARGET

Trendnet manufactures a moderate portfolio of consumer and small-business networking devices including wireless routers and access points, with its vulnerability footprint heavily concentrated in firmware components across product lines such as the TEW-827DRU and TEW-755AP. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, reflecting the memory-safety and command-parsing demands of embedded network firmware. The exposure recurs through weakness classes including out-of-bounds writes, buffer overflows, OS and general command injection, and improper memory-bounds restriction—classic firmware attack surfaces where input validation and memory isolation are foundational to security. These devices often remain operational far beyond their support lifecycle and frequently sit on network perimeters, making firmware flaws particularly consequential to defenders. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
190
Total CVEs
More Total CVEs than 100% of tracked vendors
0.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
8.3
Avg CVSS Score
Higher Avg CVSS Score than 81% of tracked vendors
0.5%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Trendnet over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 6, 2012
13 years ago
Most Recent CVE
May 29, 2026
56 days ago

Products(129 total)

Top CVEs

Signals from CVEs in this vendor scope (190 CVEs).

190 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2015-1187CRITICAL
The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ccp.
Sep 21, 20179.897YESYES
CVE-2012-4876HIGH
Stack-based buffer overflow in the UltraMJCam ActiveX Control in TRENDnet SecurView TV-IP121WN Wireless Internet Camera allows remote attackers to execute arbitrary code via a long
Sep 6, 201210.083NOYES
CVE-2021-20150MEDIUM
Trendnet AC2600 TEW-827DRU version 2.08B01 improperly discloses information via redirection from the setup wizard. Authentication can be bypassed and a user may view information as
Dec 30, 20215.352NOYES
CVE-2013-4659CRITICAL
Buffer overflow in Broadcom ACSD allows remote attackers to execute arbitrary code via a long string to TCP port 5916. This component is used on routers of multiple vendors includi
Mar 14, 20179.848NOYES
CVE-2021-20158CRITICAL
Trendnet AC2600 TEW-827DRU version 2.08B01 contains an authentication bypass vulnerability. It is possible for an unauthenticated, malicous actor to force the change of the admin p
Dec 30, 20219.847NOYES
CVE-2025-15471CRITICAL
A vulnerability was detected in TRENDnet TEW-713RE 1.02. The impacted element is an unknown function of the file /goformX/formFSrvX. The manipulation of the argument SZCMD results
Jan 7, 20269.841NONO
CVE-2026-10063CRITICAL
A vulnerability was identified in TRENDnet TEW-432BRP 3.10B20. Affected by this issue is the function formWPS of the file /goform/formWPS. Such manipulation of the argument peerPin
May 29, 20269.839NONO
CVE-2026-10062CRITICAL
A vulnerability was determined in TRENDnet TEW-432BRP 3.10B20. Affected by this vulnerability is the function formSetRoute of the file /goform/formSetRoute. This manipulation of th
May 29, 20269.839NONO
CVE-2026-10061CRITICAL
A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. Affected is the function formWPS of the file /goform/formWPS. The manipulation of the argument peerPin results in command
May 29, 20269.837NONO
CVE-2026-10060CRITICAL
A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. This impacts the function formSetRoute of the file /goform/formSetRoute. The manipulation of the argument ip/mask/gat
May 29, 20269.837NONO
View all 190 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products190 CVEs
18%
49%
32%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (1.6%)
Network162 (85.3%)
Unknown4 (2.1%)
Physical2 (1.1%)
Adjacent Network19 (10.0%)
Attack Complexity
Low179 (94.2%)
High7 (3.7%)
Unknown4 (2.1%)
User Interaction
None168 (88.4%)
Unknown4 (2.1%)
Required18 (9.5%)
Privileges Required
Low69 (36.3%)
High11 (5.8%)
None106 (55.8%)
Unknown4 (2.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (190 CVEs).

CISA KEV
1 CVE
0.5% of CVEs· 99th percentile
Metasploit
2 CVEs
1.1% of CVEs· 97th percentile
Nuclei
2 CVEs
1.1% of CVEs· 95th percentile
ExploitDB
6 CVEs
3.2% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Trendnet.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Trendnet — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Trendnet's Products

View all 4 CNAs →

Top CWEs