Trendnet manufactures a moderate portfolio of consumer and small-business networking devices including wireless routers and access points, with its vulnerability footprint heavily concentrated in firmware components across product lines such as the TEW-827DRU and TEW-755AP. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, reflecting the memory-safety and command-parsing demands of embedded network firmware. The exposure recurs through weakness classes including out-of-bounds writes, buffer overflows, OS and general command injection, and improper memory-bounds restriction—classic firmware attack surfaces where input validation and memory isolation are foundational to security. These devices often remain operational far beyond their support lifecycle and frequently sit on network perimeters, making firmware flaws particularly consequential to defenders. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Trendnet over time
Signals from CVEs in this vendor scope (190 CVEs).
190 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-1187CRITICAL The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ccp. | Sep 21, 2017 | 9.8 | 97 | YES | YES |
CVE-2012-4876HIGH Stack-based buffer overflow in the UltraMJCam ActiveX Control in TRENDnet SecurView TV-IP121WN Wireless Internet Camera allows remote attackers to execute arbitrary code via a long | Sep 6, 2012 | 10.0 | 83 | NO | YES |
CVE-2021-20150MEDIUM Trendnet AC2600 TEW-827DRU version 2.08B01 improperly discloses information via redirection from the setup wizard. Authentication can be bypassed and a user may view information as | Dec 30, 2021 | 5.3 | 52 | NO | YES |
CVE-2013-4659CRITICAL Buffer overflow in Broadcom ACSD allows remote attackers to execute arbitrary code via a long string to TCP port 5916. This component is used on routers of multiple vendors includi | Mar 14, 2017 | 9.8 | 48 | NO | YES |
CVE-2021-20158CRITICAL Trendnet AC2600 TEW-827DRU version 2.08B01 contains an authentication bypass vulnerability. It is possible for an unauthenticated, malicous actor to force the change of the admin p | Dec 30, 2021 | 9.8 | 47 | NO | YES |
CVE-2025-15471CRITICAL A vulnerability was detected in TRENDnet TEW-713RE 1.02. The impacted element is an unknown function of the file /goformX/formFSrvX. The manipulation of the argument SZCMD results | Jan 7, 2026 | 9.8 | 41 | NO | NO |
CVE-2026-10063CRITICAL A vulnerability was identified in TRENDnet TEW-432BRP 3.10B20. Affected by this issue is the function formWPS of the file /goform/formWPS. Such manipulation of the argument peerPin | May 29, 2026 | 9.8 | 39 | NO | NO |
CVE-2026-10062CRITICAL A vulnerability was determined in TRENDnet TEW-432BRP 3.10B20. Affected by this vulnerability is the function formSetRoute of the file /goform/formSetRoute. This manipulation of th | May 29, 2026 | 9.8 | 39 | NO | NO |
CVE-2026-10061CRITICAL A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. Affected is the function formWPS of the file /goform/formWPS. The manipulation of the argument peerPin results in command | May 29, 2026 | 9.8 | 37 | NO | NO |
CVE-2026-10060CRITICAL A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. This impacts the function formSetRoute of the file /goform/formSetRoute. The manipulation of the argument ip/mask/gat | May 29, 2026 | 9.8 | 37 | NO | NO |
Signals from CVEs in this vendor scope (190 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Trendnet.
Media articles that mention a CVE ID that affects a product developed by Trendnet — matched by CVE ID, not by vendor name.