CVE-2024-57590: TRENDnet Tew-632brp Firmware
Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.
TRENDnet TEW-632BRP v1.010B31 devices have an OS command injection vulnerability in the CGl interface "ntp_sync.cgi",which allows remote attackers to execute arbitrary commands via parameter "ntp_server" passed to the "ntp_sync.cgi" binary through a POST request.
Affected products
- TRENDnet Tew-632brp Firmware: version 1.010b31 only
Published 2025-01-27. Last modified 2026-06-17.