CVE-2018-19239: TRENDnet Tew-673gru Firmware
High severity, CVSS 7.2. EPSS: 5.1% chance of exploitation in the next 30 days.
TRENDnet TEW-673GRU v1.00b40 devices have an OS command injection vulnerability in the start_arpping function of the timer binary, which allows remote attackers to execute arbitrary commands via three parameters (dhcpd_start, dhcpd_end, and lan_ipaddr) passed to the apply.cgi binary through a POST request.
Affected products
- TRENDnet Tew-673gru Firmware: version 1.00b40 only
Published 2018-12-20. Last modified 2026-06-17.