Impact
A flaw in TRENDnet Router 1.1.02b01’s /cgi-bin/ping.cgi allows manipulation of the argument wan_type, resulting in command injection. Attackers can execute arbitrary commands. The vulnerability may be used to compromise the device.
Affected Systems
TRENDnet routers running firmware version 1.1.02b01. The issue resides in an unknown function within the ping.cgi CGI script, part of the router’s web interface.
Risk and Exploitability
The CVSS base score of 5.3 indicates a medium severity. No EPSS score is available and the vulnerability is not listed in the KEV catalog, which limits certainty about current exploitation rates. However, the published proof‑of‑concept code shows that a remote attacker can launch the exploit by sending a crafted HTTP request to /cgi-bin/ping.cgi with a malicious wan_type value. The description does not specify whether authentication is required, but the attack can be performed over the Internet, making it a substantial risk to exposed devices.
OpenCVE Enrichment