logo

One Request to Rule Them All: Critical Trendnet Flaw (CVE-2025-15471) Allows Total Takeover

ID: ec8dd955-2a6e-5bc4-bc9c-75c01daffe88

STIX ID: report--ec8dd955-2a6e-5bc4-bc9c-75c01daffe88

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-01-08

Date Updated: 2026-04-22

Author: Ddos

...
...

A critical pre-authentication command injection (CVE-2025-15471, CVSS 9.8) in the Trendnet TEW-713RE Wi‑Fi extender allows unauthenticated remote attackers to execute arbitrary shell commands as root via the /goformX/formFSrvX endpoint (SZCMD parameter). A researcher demonstrated exploitation in a firmware simulation; successful exploitation can fully compromise the device, enable backdoors, intercept traffic, or be used as a pivot into the local network. The report recommends removing direct shell execution, enforcing authentication, whitelisting commands, and running services with least privilege, and advises users to restrict management interface exposure until a patched firmware is available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.