CVE-2025-25428

TRENDnet TEW-929DRU 1.0.0.10 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:trendnet:tew-929dru_firmware:1.0.0.10:*:*:*:*:*:*:*
cpe:2.3:h:trendnet:tew-929dru:-:*:*:*:*:*:*:*

History

21 May 2025, 16:07

Type Values Removed Values Added
CPE cpe:2.3:o:trendnet:tew-929dru_firmware:1.0.0.10:*:*:*:*:*:*:*
cpe:2.3:h:trendnet:tew-929dru:-:*:*:*:*:*:*:*
References () https://instinctive-acapella-fc7.notion.site/Trendnet-TEW-929DRU-Hardcoded-password-17815d9d4d2680d5a2becf32425d93fd - () https://instinctive-acapella-fc7.notion.site/Trendnet-TEW-929DRU-Hardcoded-password-17815d9d4d2680d5a2becf32425d93fd - Exploit, Third Party Advisory
First Time Trendnet
Trendnet tew-929dru Firmware
Trendnet tew-929dru

04 Mar 2025, 16:15

Type Values Removed Values Added
CWE CWE-259
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.0
Summary
  • (es) Se descubrió que TRENDnet TEW-929DRU 1.0.0.10 contiene una vulnerabilidad de contraseña codificada en /etc/shadow, que permite a los atacantes iniciar sesión como superusuario.

28 Feb 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-28 19:15

Updated : 2025-05-21 16:07


NVD link : CVE-2025-25428

Mitre link : CVE-2025-25428

CVE.ORG link : CVE-2025-25428


JSON object : View

Products Affected

trendnet

  • tew-929dru
  • tew-929dru_firmware
CWE
CWE-259

Use of Hard-coded Password