CVE-2021-32426
Published Jun 17, 2021In TrendNet TW100-S4W1CA 2.3.32, it is possible to inject arbitrary JavaScript into the router's web interface via the "echo" command.
Vendor/product archive
2 CVEs tagged to trendnet / tw100-s4w1ca_firmware — 0 Critical, 1 High, 1 Medium, 0 Low, 0 Unrated.
In TrendNet TW100-S4W1CA 2.3.32, it is possible to inject arbitrary JavaScript into the router's web interface via the "echo" command.
In TrendNet TW100-S4W1CA 2.3.32, due to a lack of proper session controls, a threat actor could make unauthorized changes to an affected router via a specially crafted web page. I…