CVE-2025-8757
A vulnerability was found in TRENDnet TV-IP110WN 1.2.2 and classified as problematic. Affected by this issue is some unknown functionality of the file /server/boa.conf of the component Embedded Boa Web Server. The manipulation leads to least privilege violation. Local access is required to approach this attack. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.3
- CVSS vector
- CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
- EPSS probability
- 0.15%
- CWE
- CWE-272, CWE-266
- Published
- 2025-08-09
- Last modified
- 2026-03-12
Affected products
- TRENDnet TV-IP110WN
Weakness type
Related vulnerabilities
- CVE-2026-79693 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-79944 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2025-62299 — HCL IntelliOps Event Management is affected by multiple security vulnerabilities.
- CVE-2026-59915 — Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain a Least Privilege...
- CVE-2026-49500 — Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain an Improper Link...
- CVE-2026-15271 — TOTOLINK EX200 Web boa.conf least privilege violation
- CVE-2026-15270 — D-link DIR-823G Web boa.conf least privilege violation
- CVE-2026-11620 — TOTOLINK EX200 vsftpd vsftpd.conf least privilege violation