CVE-2025-25523

MEDIUM

Trendnet Teg-40128 Firmware - Buffer Overflow

Title source: rule
STIX 2.1

Description

Buffer overflow vulnerability in Trendnet TEG-40128 Web Smart Switch v1(1.00.023) due to the lack of length verification, which is related to the mobile access point setup operation. The attacker can directly control the remote target device by successfully exploiting this vulnerability.

References (1)

Core 1

Scores

CVSS v3 5.9
EPSS 0.0011
EPSS Percentile 29.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-120
Status published
Products (1)
trendnet/teg-40128_firmware 1.00.023
Published Feb 11, 2025
Tracked Since Feb 18, 2026