TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS) vulnerability via the ptRule_ApplicationName_1.1.6.0.0 parameter on the /special_ap.htm page.
References
Link | Resource |
---|---|
https://github.com/4hsien/CVE-vulns/blob/main/TRENDnet/TEW-652BRP/XSS_Special_AP/README.md | Exploit Third Party Advisory |
https://www.trendnet.com/products/product-detail?prod=235_TEW-651BR | Broken Link Product |
https://www.trendnet.com/products/product-detail?prod=235_TEW-652BRP | Broken Link Product |
https://www.trendnet.com/products/product-detail?prod=245_TEW-652BRU | Broken Link Product |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
History
01 Apr 2025, 18:21
Type | Values Removed | Values Added |
---|---|---|
First Time |
Trendnet
Trendnet tew-652bru Trendnet tew-651br Firmware Trendnet tew-652brp Firmware Trendnet tew-651br Trendnet tew-652bru Firmware Trendnet tew-652brp |
|
CPE | cpe:2.3:h:trendnet:tew-651br:-:*:*:*:*:*:*:* cpe:2.3:o:trendnet:tew-652bru_firmware:1.00b12:*:*:*:*:*:*:* cpe:2.3:o:trendnet:tew-652brp_firmware:3.04b01:*:*:*:*:*:*:* cpe:2.3:h:trendnet:tew-652brp:-:*:*:*:*:*:*:* cpe:2.3:h:trendnet:tew-652bru:-:*:*:*:*:*:*:* cpe:2.3:o:trendnet:tew-651br_firmware:2.04b1:*:*:*:*:*:*:* |
|
References | () https://github.com/4hsien/CVE-vulns/blob/main/TRENDnet/TEW-652BRP/XSS_Special_AP/README.md - Exploit, Third Party Advisory | |
References | () https://www.trendnet.com/products/product-detail?prod=235_TEW-651BR - Broken Link, Product | |
References | () https://www.trendnet.com/products/product-detail?prod=235_TEW-652BRP - Broken Link, Product | |
References | () https://www.trendnet.com/products/product-detail?prod=245_TEW-652BRU - Broken Link, Product |
Information
Published : 2024-11-11 20:15
Updated : 2025-04-01 18:21
NVD link : CVE-2024-51190
Mitre link : CVE-2024-51190
CVE.ORG link : CVE-2024-51190
JSON object : View
Products Affected
trendnet
- tew-651br_firmware
- tew-652bru
- tew-652brp
- tew-652brp_firmware
- tew-652bru_firmware
- tew-651br
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')