Impact
A command injection flaw exists in the /cgi-bin/admin/set_time.cgi component of TRENDnet TV-IP751WIC. The flaw allows an attacker to inject arbitrary shell commands, which are executed with the privileges of the web service running on the device. This can lead to full compromise of the device, including unauthorized configuration changes, data exfiltration, or usage as a pivot point for further network attacks. The vulnerability results from unsanitized input is classified under CWE‑74 and CWE‑77.
Affected Systems
The affected product is TRENDnet TV-IP751WIC, specifically firmware version 11.03.03. No other versions are documented as impacted. The device exposes the vulnerable CGI script over HTTP, making it reachable from any network that can reach the device's management interface.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the exploit is publicly available. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote over the network, as the CGI script can be accessed from any host with network connectivity to the device. An attacker can exploit this by sending a crafted HTTP request containing malicious commands, leading to remote code execution on the device.
OpenCVE Enrichment