CVE-2018-19240

CRITICAL

TRENDnet TV-IP110WN <V1.2.2 - Buffer Overflow

Title source: llm
STIX 2.1

Description

Buffer overflow in network.cgi on TRENDnet TV-IP110WN V1.2.2 build 68, V1.2.2.65, and V1.2.2 build 64 and TV-IP121WN V1.2.2 build 28 devices allows attackers to hijack the control flow to any attacker-specified location by crafting a POST request payload (without authentication).

References (2)

Core 2
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2018/Dec/21

Scores

CVSS v3 9.8
EPSS 0.0310
EPSS Percentile 87.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (4)
trendnet/tv-ip110wn_firmware 1.2.2.64
trendnet/tv-ip110wn_firmware 1.2.2.65
trendnet/tv-ip110wn_firmware 1.2.2.68
trendnet/tv-ip121wn_firmware 1.2.2.28
Published Dec 20, 2018
Tracked Since Feb 18, 2026