CVE-2018-19239: TRENDnet Tew-673gru Firmware

High severity, CVSS 7.2. EPSS: 5.1% chance of exploitation in the next 30 days.

TRENDnet TEW-673GRU v1.00b40 devices have an OS command injection vulnerability in the start_arpping function of the timer binary, which allows remote attackers to execute arbitrary commands via three parameters (dhcpd_start, dhcpd_end, and lan_ipaddr) passed to the apply.cgi binary through a POST request.

Affected products

  • TRENDnet Tew-673gru Firmware: version 1.00b40 only

Published 2018-12-20. Last modified 2026-06-17.