Security Advisory

CVE-2024-57590

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-01-27 00:00:00
Last updated 2025-01-28 19:46:47
Assigner mitre
State PUBLISHED

Description

TRENDnet TEW-632BRP v1.010B31 devices have an OS command injection vulnerability in the CGl interface "ntp_sync.cgi",which allows remote attackers to execute arbitrary commands via parameter "ntp_server" passed to the "ntp_sync.cgi" binary through a POST request.