CVE-2025-15137
TRENDnet TEW-800MB NTPSyncWithHost.cgi sub_F934 command injection
CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th
A vulnerability was detected in TRENDnet TEW-800MB 1.0.1.0. Affected by this vulnerability is the function sub_F934 of the file NTPSyncWithHost.cgi. The manipulation results in command injection. The attack may be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
| CWE | CWE-77 CWE-74 |
| Vendor | trendnet |
| Product | tew-800mb |
| Published | Dec 28, 2025 |
| Last Updated | Feb 24, 2026 |
Stay Ahead of the Next One
Get instant alerts for trendnet tew-800mb
Be the first to know when new high vulnerabilities affecting trendnet tew-800mb are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
TRENDnet / TEW-800MB
1.0.1.0
References
Credits
🔍 Zephyr369 (VulDB User) VulDB