CVE-2025-15471
A vulnerability was detected in TRENDnet TEW-713RE 1.02. The impacted element is an unknown function of the file /goformX/formFSrvX. The manipulation of the argument SZCMD results in os command injection. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 10
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
- EPSS probability
- 13.81%
- CWE
- CWE-78, CWE-77
- Published
- 2026-01-06
- Last modified
- 2026-03-19
Affected products
- TRENDnet TEW-713RE
Weakness type
Related vulnerabilities
- CVE-2026-13745 — Arbitrary Code Execution in Gemini CLI via Symlinked Environment Variables
- CVE-2026-88282 — GV-LPCLPC2011/2211 - Stored FTP-Username Command Injection
- CVE-2026-88277 — GV-LPCLPC2011/2211 - ONVIF Subscribe Address Command Injection
- CVE-2026-88276 — GV-LPCLPC2011/2211 - Wireless WEP Key1-Key4 Command Injection
- CVE-2026-88275 — GV-LPC2011/LPC2211 - Wireless WPA-PSK Command Injection
- CVE-2026-88274 — GV-LPC2011/LPC2211 - Wireless SSID Command Injection
- CVE-2026-88273 — GV-LPC2011/LPC2211 - PPPoE Username Shell-Configuration Command Injection
- CVE-2026-88272 — GV-LPC2011/LPC2211 - Stored Administrator-Username Command Injection