A vulnerability has been found in TRENDnet TEW-822DRE 1.00B21/1.01B06. This affects the function sub_43ACF4  of the file /boafrm/formWsc. Such manipulation of the argument peerPin leads to command injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 07 Jan 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Trendnet tew-822dre Firmware
CPEs cpe:2.3:h:trendnet:tew-822dre:-:*:*:*:*:*:*:*
cpe:2.3:o:trendnet:tew-822dre_firmware:1.00b21:*:*:*:*:*:*:*
cpe:2.3:o:trendnet:tew-822dre_firmware:1.01b06:*:*:*:*:*:*:*
Vendors & Products Trendnet tew-822dre Firmware

Mon, 29 Dec 2025 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Trendnet
Trendnet tew-822dre
Vendors & Products Trendnet
Trendnet tew-822dre

Mon, 29 Dec 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 28 Dec 2025 14:15:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in TRENDnet TEW-822DRE 1.00B21/1.01B06. This affects the function sub_43ACF4  of the file /boafrm/formWsc. Such manipulation of the argument peerPin leads to command injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title TRENDnet TEW-822DRE formWsc sub_43ACF4  command injection
Weaknesses CWE-74
CWE-77
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2025-12-29T16:06:45.224Z

Reserved: 2025-12-27T10:12:39.744Z

Link: CVE-2025-15139

cve-icon Vulnrichment

Updated: 2025-12-29T16:06:39.983Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-28T14:16:27.603

Modified: 2026-01-07T15:00:16.850

Link: CVE-2025-15139

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-29T22:33:18Z

Weaknesses