← Back to CVE List
Vulnerability Intelligence Report

CVE-2024-51190

TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS) vulnerability via the ptRule_ApplicationName_1.1.6.0.0 parameter on the /special_ap.htm page.

No Active Exploit Signals
CVSS Base Score
4.8
MEDIUM
Exploitability:1.7
Impact Score:2.8
EPSS Probability:0.38%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-79 ↗CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected Products & Versions

Vendor Product Affected Versions
trendnet tew-651br_firmware 2.04b1
trendnet tew-651br all
trendnet tew-652brp_firmware 3.04b01
trendnet tew-652brp all
trendnet tew-652bru_firmware 1.00b12
trendnet tew-652bru all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.384%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2024-10-28T00:00:00
Published2024-11-11T00:00:00
Last Updated2024-11-12T01:58:32

LINK COPIED TO CLIPBOARD